CVE-2025-3010

EUVD-2025-8869
A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this issue is the function glslang::TIntermediate::isConversionAllowed of the file glslang/MachineIndependent/Intermediate.cpp. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.97%
Debian logo
Debian Releases
Debian Product
Codename
glslang
bookworm
unimportant
bullseye
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glslang
focal
deferred
jammy
deferred
noble
deferred
oracular
ignored
plucky
ignored
questing
ignored
resolute
deferred
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
glslang
Amazon Linux 2023
0:15.0.0-88.amzn2023
fixed
glslang-debuginfo
Amazon Linux 2023
0:15.0.0-88.amzn2023
fixed
glslang-debugsource
Amazon Linux 2023
0:15.0.0-88.amzn2023
fixed
glslang-devel
Amazon Linux 2023
0:15.0.0-88.amzn2023
fixed