CVE-2023-29531
published 2023-06-19CVE-2023-29531: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.97%
58.1th percentile
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash.
*This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 112.0 | 112.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 112 | 112 |
| mozilla | firefox_esr | < 102.10 | 102.10 |
| mozilla | firefox_esr | >= unspecified < 102.10 | 102.10 |
| mozilla | thunderbird | < 102.10 | 102.10 |
| mozilla | thunderbird | >= unspecified < 102.10 | 102.10 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Out-of-bound memory access in WebGL on macOS
vendor_redhat·2023-04-11·CVSS 9.8
CVE-2023-29531 [CRITICAL] CWE-787 Mozilla: Out-of-bound memory access in WebGL on macOS
Mozilla: Out-of-bound memory access in WebGL on macOS
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash.
*This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
The Mozilla Foundation Security Advisory describes this flaw as:
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash.
*This bug only affects Firefox for macOS. Other operating systems are unaffected.*
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security
Debian
CVE-2023-29531: firefox - An attacker could have caused an out of bounds memory access using WebGL APIs, l...
vendor_debian·2023·CVSS 9.8
CVE-2023-29531 [CRITICAL] CVE-2023-29531: firefox - An attacker could have caused an out of bounds memory access using WebGL APIs, l...
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-14: CVE-2023-29531
vendor_mozilla·CVSS 9.8
CVE-2023-29531 [CRITICAL] Mozilla Foundation Security Advisory 2023-14: CVE-2023-29531
Mozilla Foundation Security Advisory 2023-14
CVE: CVE-2023-29531
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.10
Mozilla
Mozilla Foundation Security Advisory 2023-15: CVE-2023-29531
vendor_mozilla·CVSS 9.8
CVE-2023-29531 [CRITICAL] Mozilla Foundation Security Advisory 2023-15: CVE-2023-29531
Mozilla Foundation Security Advisory 2023-15
CVE: CVE-2023-29531
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.10
Mozilla
Mozilla Foundation Security Advisory 2023-13: CVE-2023-29531
vendor_mozilla·CVSS 9.8
CVE-2023-29531 [CRITICAL] Mozilla Foundation Security Advisory 2023-13: CVE-2023-29531
Mozilla Foundation Security Advisory 2023-13
CVE: CVE-2023-29531
Product: Firefox, Firefox for Android, Focus for Android
Impact: high
Fixed in: Firefox 112
Firefox for Android 112
Focus for Android 112
GHSA
GHSA-x2cj-cp2c-fxvp: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash
ghsa_unreviewed·2023-06-19
CVE-2023-29531 [CRITICAL] CWE-787 GHSA-x2cj-cp2c-fxvp: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash.
*This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
OSV
CVE-2023-29531: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash
osv·2023-06-19·CVSS 9.8
CVE-2023-29531 [CRITICAL] CVE-2023-29531: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
No detection rules found.
No public exploits indexed.
Bugzilla
WebGL macOS GLSL Shader Out-Of-Bounds Vulnerability
bugzilla·2024-03-28
WebGL macOS GLSL Shader Out-Of-Bounds Vulnerability
WebGL macOS GLSL Shader Out-Of-Bounds Vulnerability
Created attachment 9393705
oob.html
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
Steps to reproduce:
Steps to reproduce:
Operating System: MacOS Sonoma 14.4 [Macbook ARM]
1. python3 -m http.server 9292
2. Open Firefox
3. Open http://localhost:9292/poc.html
Actual results:
```
==5988==ERROR: AddressSanitizer: BUS on unknown address (pc 0x00018e29dd74 bp 0x000173983120 sp 0x000173982f10 T50)
==5988==The signal is caused by a READ memory access.
==5988==Hint: this fault was caused by a dereference of a high value address (see register values below). Disassemble the provided pc to learn which register was used.
#0 0x18e29dd74 in ___chkstk_darwin+0x3c (l
Bugzilla
Firefox WebGL DrawElementsInstanced Heap-Buffer-Overflow Possibly leading to Sandbox Escape Vulnerability (Mesa VM driver / Linux)
bugzilla·2023-07-16
Firefox WebGL DrawElementsInstanced Heap-Buffer-Overflow Possibly leading to Sandbox Escape Vulnerability (Mesa VM driver / Linux)
Firefox WebGL DrawElementsInstanced Heap-Buffer-Overflow Possibly leading to Sandbox Escape Vulnerability (Mesa VM driver / Linux)
Created attachment 9344057
poc.html
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
Steps to reproduce:
## **Title**
- Firefox WebGL DrawElementsInstanced Heap-Buffer-Overflow Vulnerability
## **Summary**
- A Heap-Buffer-Overflow vulnerability exists in the WebGL DrawElementsInstanced
- The browser process crashes when triggering this bug.
## **Test environment**
- Product : Firefox Stable & Firefox ASan Build Opt
- VM : Virtualbox 7.0.8
- GUEST OS : Ubuntu Desktop 23.04
## ASan
```jsx
==11034==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x6310051f36c8 at pc 0x55
https://bugzilla.mozilla.org/show_bug.cgi?id=1794292https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/https://bugzilla.mozilla.org/show_bug.cgi?id=1794292https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/
2023-06-19
Published