Vulnerability Description
naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
CVSS Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gfx-Rs | Wgpu | < 25.0.0 |
| Gfx-Rs | Naga | < 25.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/MageWeiG/VulnerabilityCollection/blob/main/CVE-2024-36761/infThird Party Advisory
- https://github.com/gfx-rs/naga/issues/2591ExploitIssue TrackingThird Party Advisory
- https://github.com/MageWeiG/VulnerabilityCollection/blob/main/CVE-2024-36761/infThird Party Advisory
- https://github.com/gfx-rs/naga/issues/2591ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2024-36761?
CVE-2024-36761 is a vulnerability with a CVSS score of 9.8 (CRITICAL). naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
How severe is CVE-2024-36761?
CVE-2024-36761 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-36761?
Check the references section above for vendor advisories and patch information. Affected products include: Gfx-Rs Wgpu, Gfx-Rs Naga.