Logo
vulnerabilityCVE-2023-33863
Name
CVE-2023-33863
Source
NVD ( link)Debian ( link)
Description
SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
renderdoc
Patched

Vulnerability Ratings#


9.8
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
1.38
Not Affected
yocto
scarthgap
1.27
Not Affected

Resolved with patches#


renderdoc (yocto:kirkstone)

#
Title
Author
Resolve
1
Verify array sizes when serialising for strings
baldurk <baldurk@baldurk.org>
CVE-2023-33863
CVE-2023-33864
CVE-2023-33865