Mesa 23.0.4 was discovered to contain a NULL pointer dereference in checkxshm() for the haserror state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.
glxpbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
An Out-of-bounds memory read / write flaw was found in Mesa. A remote attacker could use this flaw to crash an application linked against or, potentially, execute arbitrary code via an application linked against Mesa graphics libraries.
References:
https://bugs.freedesktop.org/showbug.cgi?id=59429 https://code.google.com/p/chromium/issues/detail?id=169054 (private) https://bugzilla.mozilla.org/showbug.cgi?id=827106 (private)