CVE-2023-45919
NixOS vulnerability analysis and mitigation

Overview

Mesa 23.0.4 contains a buffer over-read vulnerability in the glXQueryServerString() function (CVE-2023-45919). The vulnerability was discovered and disclosed in January 2024, affecting the Mesa graphics library. This is a disputed vulnerability as there are no common situations in which users require uninterrupted operation with an attacker-controlled server (NVD).

Technical details

The vulnerability stems from the glXQueryServerString() function trusting the on-the-wire string length returned in the xcb_glx_query_server_string_reply_t message without proper validation. The function uses an unchecked length value from the reply to allocate memory and perform a memcpy operation, which can lead to a buffer over-read condition. The CVSS v3.1 base score is 5.3 (Medium), with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L. The vulnerability is classified as CWE-126 (Buffer Over-read) (NVD, Mesa Issue).

Impact

The buffer over-read vulnerability could potentially lead to information disclosure or system crashes. However, the practical impact is limited since it requires an attacker-controlled server, which is not a common operational scenario (NVD).

Exploitability

The vulnerability requires local access and user interaction to exploit. The attack complexity is low, but no privilege escalation is required. There are no reports of this vulnerability being exploited in the wild (Full Disclosure).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86993MEDIUM5.9
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86996MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86995MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86994MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86085MEDIUM5.1
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management