Bugzilla – Bug 1222040
VUL-0: CVE-2023-45913: Mesa: NULL pointer dereference via dri2GetGlxDrawableFromXDrawableId()
Last modified: 2024-03-27 10:13:37 UTC
Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-45913 http://seclists.org/fulldisclosure/2024/Jan/28 https://gitlab.freedesktop.org/mesa/mesa/-/issues/9856 https://seclists.org/fulldisclosure/2024/Jan/71 https://www.cve.org/CVERecord?id=CVE-2023-45913
Ok. Thanks. Not sure what to do with this now. I would like to at least watch the issue on gitlab fdo, but seems this is not supported. I could try to poll this from time to time. But no promises given.