Critical severity9.8NVD Advisory· Published Jun 7, 2023· Updated Jun 17, 2026
CVE-2023-33864
CVE-2023-33864
Description
StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It uses uint32_t(m_BufferSize-m_InputSize) even though m_InputSize can exceed m_BufferSize.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- RenderDoc/RenderDocdescription
- osv-coords3 versionspkg:rpm/opensuse/renderdoc&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/renderdoc&distro=openSUSE%20Tumbleweedpkg:rpm/suse/renderdoc&distro=SUSE%20Package%20Hub%2015%20SP5
< 1.24-bp155.2.3.1+ 2 more
- (no CPE)range: < 1.24-bp155.2.3.1
- (no CPE)range: < 1.27-1.1
- (no CPE)range: < 1.24-bp155.2.3.1
Patches
Vulnerability mechanics
References
7- packetstormsecurity.com/files/172804/RenderDoc-1.26-Local-Privilege-Escalation-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2023/Jun/2nvdExploitMailing ListThird Party Advisory
- www.qualys.com/2023/06/06/renderdoc/renderdoc.txtnvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/07/msg00023.htmlnvdThird Party Advisory
- renderdoc.orgnvdProduct
- lists.debian.org/debian-lts-announce/2024/12/msg00008.htmlnvd
- security.gentoo.org/glsa/202311-10nvd
News mentions
0No linked articles in our index yet.