Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to
VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.
Metrics
Affected Vendors & Products
References
History
Tue, 06 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 | |
Metrics |
cvssV3_1
|
Tue, 06 May 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description. | |
References |
|

Status: PUBLISHED
Assigner: ChromeOS
Published: 2025-05-06T00:59:32.231Z
Updated: 2025-05-08T19:15:07.601Z
Reserved: 2025-03-18T20:10:07.777Z
Link: CVE-2025-2509

Updated: 2025-05-06T13:35:05.669Z

Status : Awaiting Analysis
Published: 2025-05-06T01:15:50.563
Modified: 2025-05-07T14:13:35.980
Link: CVE-2025-2509

No data.