CVE-2012-2864

critical
Published 2012-08-22 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

Mesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, allows remote attackers to execute arbitrary code via unspecified vectors that trigger an "array overflow."

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2012-2864 NameCVE-2012-2864 DescriptionMesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, allows remote attackers to execute arbitrary code via unspecified vectors that trigger an "array overflow." SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat,โ€ฆ

CVE-2012-2864

NameCVE-2012-2864
DescriptionMesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, allows remote attackers to execute arbitrary code via unspecified vectors that trigger an "array overflow."
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs685667

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mesa (PTS)bullseye20.3.5-1fixed
bookworm22.3.6-1+deb12u1fixed
trixie25.0.7-2fixed
forky26.0.6-1fixed
sid26.0.8-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mesasourcesqueeze(not affected)
mesasource(unstable)8.0.4-2685667

Notes

[squeeze] - mesa <not-affected> (Vulnerable code not present)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[squeeze] - mesa <not-affected> (Vulnerable code not present)

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 8.0.4-2
sid Fixed 8.0.4-2
forky Fixed 8.0.4-2
bullseye Fixed 8.0.4-2
bookworm Fixed 8.0.4-2

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.