Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Link | Tags |
---|---|
https://gitlab.freedesktop.org/mesa/mesa/-/issues/9858 | vendor advisory exploit |
http://seclists.org/fulldisclosure/2024/Jan/47 | mailing list third party advisory |