PT-2024-13301 · Mesa+2 · Mesa+2

Meng Ruijie

·

Published

2024-03-26

·

Updated

2025-08-29

·

CVE-2023-45919

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Mesa version 23.0.4
Description A buffer over-read was discovered in the glXQueryServerString() function. This issue is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controlled server.
Recommendations For Mesa version 23.0.4, consider disabling the glXQueryServerString() function until a patch is available.

Fix

Buffer Over-read

Weakness Enumeration

Related Identifiers

CVE-2023-45919
ECHO-A912-8212-3FB4
OPENSUSE-SU-2024:14475-1
OPENSUSE-SU-2024_3540-1
OPENSUSE-SU-2024_3544-1
OPENSUSE-SU-2024_3548-1
SUSE-SU-2024:3526-1
SUSE-SU-2024:3540-1
SUSE-SU-2024:3544-1
SUSE-SU-2024:3548-1
SUSE-SU-2025:02803-1
SUSE-SU-2025:20082-1
SUSE-SU-2025:20664-1

Affected Products

Debian
Mesa
Suse