Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 29 May 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mesa3d
Mesa3d mesa
CPEs cpe:2.3:a:mesa3d:mesa:23.0.4:*:*:*:*:*:*:*
Vendors & Products Mesa3d
Mesa3d mesa

Thu, 07 Nov 2024 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-07T11:12:11.352Z

Reserved: 2023-10-16T00:00:00

Link: CVE-2023-45913

cve-icon Vulnrichment

Updated: 2024-08-02T20:29:32.583Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-27T04:15:10.590

Modified: 2025-05-29T15:31:20.253

Link: CVE-2023-45913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.