CVE-2023-6856Out-of-bounds Write in Mozilla Firefox

Severity
8.8HIGHNVD
EPSS
11.0%
top 6.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 19
Latest updateJan 2

Description

The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified121
NVDmozilla/firefox< 121.0
CVEListV5mozilla/firefox_esrunspecified115.6
NVDmozilla/firefox_esr< 115.6
CVEListV5mozilla/thunderbirdunspecified115.6

Also affects: Debian Linux 10.0, 11.0, 12.0

🔴Vulnerability Details

4
OSV
firefox vulnerabilities2024-01-02
GHSA
GHSA-9846-hqmr-2486: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver2023-12-19
CVEList
CVE-2023-6856: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver2023-12-19
OSV
CVE-2023-6856: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver2023-12-19

📋Vendor Advisories

8
Ubuntu
Firefox vulnerabilities2024-01-02
Ubuntu
Thunderbird vulnerabilities2024-01-02
Red Hat
Mozilla: Heap-buffer-overflow affecting WebGL <code>DrawElementsInstanced</code> method with Mesa VM driver2023-12-19
Microsoft
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution an2023-12-12
Debian
CVE-2023-6856: firefox - The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overfl...2023
CVE-2023-6856 — Out-of-bounds Write in Mozilla Firefox | cvebase