yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-33863
Component Overview
Vulnerability Overview
Name
CVE-2023-33863
Source
NVD (
link
)
Debian (
link
)
Description
SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.
CWEs
CWE-190
CWE-190
Published Date
Jun 7, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://packetstormsecurity.com/files/172804/RenderDoc-1.26-Local-Privilege-Escalation-Remote-Code-Execution.html
Exploit
http://seclists.org/fulldisclosure/2023/Jun/2
Exploit
https://lists.debian.org/debian-lts-announce/2023/07/msg00023.html
Third Party Advisory
https://renderdoc.org/
Product
https://www.qualys.com/2023/06/06/renderdoc/renderdoc.txt
Exploit
http://packetstormsecurity.com/files/172804/RenderDoc-1.26-Local-Privilege-Escalation-Remote-Code-Execution.html
Exploit
http://seclists.org/fulldisclosure/2023/Jun/2
Exploit
https://lists.debian.org/debian-lts-announce/2023/07/msg00023.html
Third Party Advisory
https://renderdoc.org/
Product
https://www.qualys.com/2023/06/06/renderdoc/renderdoc.txt
Exploit
Analysis
#
Affected Component
Analysis
renderdoc
Patched
Vulnerability Ratings
#
9.8
CVSSv31
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
renderdoc
yocto
master
1.38
Not Affected
renderdoc
yocto
scarthgap
1.27
Not Affected
Resolved with patches
#
renderdoc (yocto:kirkstone)
#
Title
Author
Resolve
1
Verify array sizes when serialising for strings
baldurk <baldurk@baldurk.org>
CVE-2023-33863
CVE-2023-33864
CVE-2023-33865