Vulnerability CVE-2023-45913


Published: 2024-03-27

Description:
Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.

 References:
https://gitlab.freedesktop.org/mesa/mesa/-/issues/9856
http://seclists.org/fulldisclosure/2024/Jan/28
https://seclists.org/fulldisclosure/2024/Jan/71

Copyright 2026, cxsecurity.com

 

Back to Top