CVE-2024-6600

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Configurations

No configuration.

History

29 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-770
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

16 Jul 2024, 18:15

Type Values Removed Values Added
Summary
  • (es) Debido a que las grandes comprobaciones de asignación en Angle para los sombreadores GLSL son demasiado indulgentes, podría ocurrir un acceso fuera de los límites al asignar más de 8192 entradas en la memoria privada del sombreador en Mac OS. Esta vulnerabilidad afecta a Firefox &lt; 128 y Firefox ESR &lt; 115.13.
Summary (en) Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13. (en) Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
References
  • () https://www.mozilla.org/security/advisories/mfsa2024-31/ -
  • () https://www.mozilla.org/security/advisories/mfsa2024-32/ -

09 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 15:15

Updated : 2024-10-29 20:35


NVD link : CVE-2024-6600

Mitre link : CVE-2024-6600

CVE.ORG link : CVE-2024-6600


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling