cbcvebase.
CVE-2023-6856
published 2023-12-19

CVE-2023-6856: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an…

PriorityP262high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
20.47%
97.2th percentile
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfirefox< firefox 121.0-1 (sid)firefox 121.0-1 (sid)
debianfirefox-esr< firefox 121.0-1 (sid)firefox 121.0-1 (sid)
debianthunderbird< firefox 121.0-1 (sid)firefox 121.0-1 (sid)
mozillafirefox< 121.0121.0
mozillafirefox
mozillafirefox>= 0 < 121.0+build1-0ubuntu0.20.04.1121.0+build1-0ubuntu0.20.04.1
mozillafirefox>= 0 < 121.0.1+build1-0ubuntu0.20.04.1121.0.1+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 121121
mozillafirefox_esr< 115.6115.6
mozillafirefox_esr>= unspecified < 115.6115.6
mozillathunderbird< 115.6115.6
mozillathunderbird>= 0 < 1:115.6.0-1~deb11u11:115.6.0-1~deb11u1
mozillathunderbird>= 0 < 1:115.6.0-1~deb12u11:115.6.0-1~deb12u1
mozillathunderbird>= 0 < 1:115.6.0-11:115.6.0-1
mozillathunderbird>= 0 < 1:115.6.0-11:115.6.0-1
mozillathunderbird>= 0 < 1:115.6.0+build2-0ubuntu0.20.04.11:115.6.0+build2-0ubuntu0.20.04.1
mozillathunderbird>= 0 < 1:115.6.0+build2-0ubuntu0.22.04.11:115.6.0+build2-0ubuntu0.22.04.1
mozillathunderbird>= unspecified < 115.6115.6
msrcazl3_mozjs_102.15.1-1_on_azure_linux_3.0

Detection & IOCsextracted from sources · hover to see the quote

  • Target the WebGL `DrawElementsInstanced` method specifically on systems using the Mesa VM driver — heap buffer overflow triggered via this WebGL call is the attack vector for CVE-2023-6856.
  • Exploitation can result in remote code execution AND sandbox escape — monitor for renderer/content process spawning unexpected child processes or accessing resources outside the sandbox boundary in Firefox/Thunderbird on Mesa VM driver systems.
  • Scope of vulnerable products: Firefox < 121, Firefox ESR < 115.6, Thunderbird < 115.6 — flag any of these unpatched versions running on Mesa VM driver environments as high-priority targets.
  • ·The vulnerability is only exploitable on systems using the Mesa VM driver — deployments using other GPU/graphics drivers are not affected by this specific heap overflow path.
  • ·Debian scopes this as 'local' impact, which may affect detection priority in purely remote-access threat models; however, the NVD and Mozilla advisories describe remote code execution as a possible outcome.
  • ·Microsoft notes Azure Linux (Mariner) as a potentially affected product due to inclusion of the open-source library; customer action is required for those environments.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.