← Vulnerability feed

Vulnerability record · CVE-2023-45913 · published 27 March 2024

CVE-2023-45913: Mesa3d mesa null pointer dereference vulnerability

Mesa3d · Mesa

Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.

6.2 CVSS 3.1 Medium EPSS 0.28% · top 81.8% CWE-476 · NULL pointer dereference
6.2CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-45913 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-40393Mesa3d mesa out-of-bounds write vulnerabilityIn Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an …EPSS 0.62%7.5CVE-2023-45931Mesa3d mesa null pointer dereference vulnerabilityMesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no …EPSS 1.0%6.8CVE-2013-1872Mesa3d mesa memory buffer overflow vulnerabilityThe Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly…EPSS 2.6%6.8CVE-2013-1993Mesa3d mesa vulnerabilityMultiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overfl…EPSS 2.7%5.3CVE-2023-45919Mesa3d mesa vulnerabilityMesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in …EPSS 0.39%4.4CVE-2019-5068Mesa3d mesa incorrect permission assignment vulnerabilityAn exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the…EPSS 0.48%4.3CVE-2023-45922Mesa3d mesa vulnerabilityglx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed beca…EPSS 0.54%6.2CVE-2026-21525Windows Remote Access Connection Manager null pointer dereference DoSWindows Remote Access Connection Manager contains a null pointer dereference (CWE-476) that lets an unauthorized attacker deny service locally. The f…KEVEPSS 4.8%analysed

Source: NIST National Vulnerability Database (record CVE-2023-45913), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.