[Bug 1950940] Re: Integer underflow in the vrend_decode_set_shader_images() on virglrenderer

2022-04-12 Thread Jun Yao
irglrenderer/-/merge_requests/654 > . It does not look like these fixes have landed in a release yet upstream. These two problems had been reported to the upstream, and they have been fixed. As they are security problem, I marked the issues confidential and they are not visible for others. > Jun Yao, was a

[Bug 1950940] Re: Integer underflow in the vrend_decode_set_shader_images() on virglrenderer

2022-03-13 Thread Jun Yao
> Hello Jun Yao, the upstream bug is still private -- is there progress being made upstream? Hi Seth, this problem has been fixed on upstream. Thanks ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubu

[Bug 1950941] Re: Integer underflow in the vrend_decode_set_shader_buffers() on virglrenderer

2022-01-06 Thread Jun Yao
at the user mode of the host (on the qemu context). So, the guest can corrupt memory of the host. And this is a security bug. Thanks, Jun Yao -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1950941 Ti

[Bug 1950941] Re: Integer underflow in the vrend_decode_set_shader_buffers() on virglrenderer

2021-12-29 Thread Jun Yao
Hi Seth Arnold, > What I'm not sure about is if this is actually a security issue or if this is just a bug -- is there actually a security boundary that is being breached? I believe that this is a security issue, which causes OOB writing in the vrend_set_single_ssbo(): 2973 void vrend_set_singl