Bugzilla – Bug 1222036
VUL-0: CVE-2023-45924: libglvnd: segmentation violation via glXGetDrawableScreen()
Last modified: 2024-07-18 13:23:01 UTC
libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-45924 https://www.cve.org/CVERecord?id=CVE-2023-45924 http://seclists.org/fulldisclosure/2024/Jan/52 https://gitlab.freedesktop.org/glvnd/libglvnd/-/issues/242
Ok. Thanks. Not sure what to do with this now. I would like to at least watch the issue on gitlab fdo, but seems this is not supported. I could try to poll this from time to time. But no promises given.
Seems there is a proposal now. https://gitlab.freedesktop.org/glvnd/libglvnd/-/merge_requests/295
(In reply to Stefan Dirsch from comment #3) > Seems there is a proposal now. > > https://gitlab.freedesktop.org/glvnd/libglvnd/-/merge_requests/295 Seems nobody is interesting into reviewing it. :-(