Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.
https://security.gentoo.org/glsa/201707-06
https://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.html
https://cgit.freedesktop.org/virglrenderer/commit/?id=114688c526fe45f341d75ccd1d85473c3b08f7a7
https://bugzilla.redhat.com/show_bug.cgi?id=1422452