Update X.Org Server 21.1.11 addresses 6 vulnerabilities

Corrective releases X.Org Server 21.1.11 and the DDX component (Device-Dependent X) xwayland 23.2.4 have been published, enabling the X.Org Server to run X11 applications in Wayland-based environments. The new versions address six vulnerabilities, some of which could be exploited for privilege escalation on systems where the X server runs with root privileges, as well as for remote code execution in configurations using X11 session forwarding via SSH.

Identified issues:

  • CVE-2023-6816 — a buffer overflow that occurs when an incorrect array index is passed in DeviceFocusEvent and ProcXIQueryPointer operations. The vulnerability arises because the X server allocates memory for the array based on the actual number of buttons, while the query allows values up to 255 to be used in the array. The issue has been present since the release of xorg-server-1.13.0 (2012).
  • CVE-2024-0229 — a write beyond the buffer boundary through rebinding to another master device in a configuration where the device is equipped with both button and key input elements, while the number of buttons (numButtons parameter) is set to 0. The issue has been present since the release of xorg-server-1.1.1 (2006).
  • CVE-2024-21885 — a buffer overflow in the XISendDeviceHierarchyEvent function, occurring when a device with a specified identifier is removed and a device with the same identifier is added within the same request. The vulnerability is caused by the double operation for a single identifier leading to two instances of the xXIHierarchyInfo structure being written, while the XISendDeviceHierarchyEvent function allocates memory for only one instance. The issue has been present since the release of xorg-server-1.10.0 (2010).
  • CVE-2024-21886 — a buffer overflow in the DisableDevice function, occurring when a master device is disabled while slave devices are already disabled. The vulnerability is caused by an incorrect calculation of the size of the structure to hold the device list. The issue has been present since the release of xorg-server-1.13.0 (2012).
  • CVE-2024-0409, CVE-2024-0408 — SELinux context corruption when enabling xserver_object_manager and running a client or creating a GLX PBuffer.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster