Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-59463.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-59463
Upstream
Published
2025-03-31T20:15:16Z
Modified
2026-04-01T05:19:51.651077Z
Summary
CVE-2025-3010 affecting package glslang 14.0.0-2
Details

A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this issue is the function glslang::TIntermediate::isConversionAllowed of the file glslang/MachineIndependent/Intermediate.cpp. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

References

Affected packages

Azure Linux:3 / glslang

Package

Name
glslang
Purl
pkg:rpm/azure-linux/glslang

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
14.0.0-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-59463.json"