We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2509



Description

Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.

Reserved 2025-03-18 | Published 2025-05-06 | Updated 2025-05-08 | Assigner ChromeOS

Problem types

Memory Corruption

Product status

16093.57.0 before 16093.57.0
affected

References

issuetracker.google.com/issues/385851796

issues.chromium.org/issues/b/385851796

cve.org (CVE-2025-2509)

nvd.nist.gov (CVE-2025-2509)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2509

Support options

Helpdesk Chat, Email, Knowledgebase