The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.1750.152, does not check whether a certain position is within the bounds of a shared-memory segment, which allows remote attackers to cause a denial of service (GPU command-buffer memory corruption) or possibly have unspecified other impact via unknown vectors.
2014-03-16T14:06:45.570
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | chrome_os | ≤ 33.0.1750.149 | Yes | |
Operating System | chrome_os | 33.0.1750.2 | Yes | |
Operating System | chrome_os | 33.0.1750.5 | Yes | |
Operating System | chrome_os | 33.0.1750.16 | Yes | |
Operating System | chrome_os | 33.0.1750.29 | Yes | |
Operating System | chrome_os | 33.0.1750.51 | Yes | |
Operating System | chrome_os | 33.0.1750.58 | Yes | |
Operating System | chrome_os | 33.0.1750.70 | Yes | |
Operating System | chrome_os | 33.0.1750.93 | Yes | |
Operating System | chrome_os | 33.0.1750.112 | Yes | |
Operating System | chrome_os | 33.0.1750.124 | Yes |