PT-2023-32970 · Microsoft · Directxtex

Published

2023-01-26

·

Updated

2023-01-26

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions DirectXTex versions prior to January 31, 2023
Description A memory overwrite bug was reported in the ConvertToSinglePlane method when given an invalid height for planar video textures. This issue affects clients of the library who use the ConvertToSinglePlane method for converting multi-planar video formats, but does not impact the use of the DDS texture loader itself.
Recommendations For versions prior to January 31, 2023, update to the January 31, 2023 or later release of DirectXTex to fix the issue. As a temporary workaround, validate that the width and height alignment requirements are met for the input image before calling the ConvertToSinglePlane function.

Fix

Related Identifiers

GHSA-3W9W-9833-GCPV

Affected Products

Directxtex