PT-2024-13299 · Mesa+2 · Mesa+2
Meng Ruijie
·
Published
2024-03-26
·
Updated
2025-08-29
·
CVE-2023-45913
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mesa version 23.0.4
Description
A NULL pointer dereference was discovered in Mesa via the function
dri2GetGlxDrawableFromXDrawableId(). This issue is triggered when the X11 server sends a DRI2 BufferSwapComplete event unexpectedly while the application is using DRI3. It is noted that the vulnerability is disputed as there is no demonstrated scenario.Recommendations
For Mesa version 23.0.4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Mesa
Suse