-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| directxtex_desktop_2019 | nuget | < 2023.1.31.1 | 2023.1.31.1 |
| directxtex_desktop_win10 | nuget | < 2023.1.31.1 | 2023.1.31.1 |
| directxtex_uwp | nuget | < 2023.1.31.1 | 2023.1.31.1 |
The vulnerability description explicitly identifies ConvertToSinglePlane as the vulnerable function when processing planar formats. The GitHub PR (#307) confirms fixes were made to add height alignment validation in this function. While other components (DDS loader, ComputePitch) received hardening, the primary vulnerability exists in ConvertToSinglePlane's failure to validate input dimensions before memory operations. The function's direct role in planar format conversion and explicit mention in all vulnerability reports justify high confidence.
KEV Misses 88% of Exploited CVEs- Get the report