CVE-2024-6600: Memory corruption in WebGL API
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS.
Other sources
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.2-2 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.3.1esr-1~deb11u1Fixed in 115.14.0esr-1~deb12u1Fixed in 128.3.1esr-1~deb12u1Fixed in 128.3.0esr-2Fixed in 128.3.1esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:115.16.0esr-1~deb11u1Fixed in 1:115.12.0-1~deb12u1Fixed in 1:115.16.0esr-1~deb12u1Fixed in 1:128.2.0esr-1Fixed in 1:128.3.0esr-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.13 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 128
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6600?
CVE-2024-6600 has been rated as a high-severity vulnerability due to the potential for out-of-bounds memory access.
How do I fix CVE-2024-6600?
To fix CVE-2024-6600, update Mozilla Thunderbird to version 128 or later and Mozilla Firefox to version 128 or later.
Which software is affected by CVE-2024-6600?
CVE-2024-6600 affects Mozilla Thunderbird and Mozilla Firefox versions prior to 128, as well as specific Debian packages.
What kind of vulnerability is CVE-2024-6600?
CVE-2024-6600 is an out-of-bounds access vulnerability that can occur during the allocation of private shader memory.
Is there a workaround available for CVE-2024-6600?
There is no known workaround for CVE-2024-6600, so updating to the latest versions is recommended.