CVE-2023-6856: Buffer Overflow
Last updated 24 July 2024
Other sources
The WebGL DrawElementsInstanced method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-54/#CVE-2023-6856
— Red Hat
The WebGL DrawElementsInstanced method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
— MITRE
The WebGL DrawElementsInstanced method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6856?
CVE-2023-6856 is classified as a critical vulnerability due to its potential to allow remote code execution and sandbox escape.
How do I fix CVE-2023-6856?
To mitigate CVE-2023-6856, users should upgrade affected software to versions 115.6 or later for Thunderbird and Firefox, as well as 121 for newer Firefox versions.
Which software is affected by CVE-2023-6856?
CVE-2023-6856 affects Mozilla Thunderbird and Mozilla Firefox, specifically versions prior to 115.6 and newer than 121.
What type of vulnerability is CVE-2023-6856?
CVE-2023-6856 is a heap buffer overflow vulnerability that occurs in the WebGL DrawElementsInstanced method.
Can CVE-2023-6856 be exploited remotely?
Yes, CVE-2023-6856 can be exploited remotely, potentially allowing an attacker to execute arbitrary code on a vulnerable system.