Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://gitlab.freedesktop.org/mesa/mesa/-/issues/9859 | vendor advisory exploit |
https://seclists.org/fulldisclosure/2024/Jan/71 | mailing list third party advisory |