X.Org Server 21.1.14 update addressing a vulnerability

Correction releases for X.Org Server 21.1.14 and the DDX component (Device-Dependent X) xwayland 24.1.4 have been published, enabling the launch of X.Org Server for running X11 applications in Wayland-based environments. The new versions address a vulnerability (CVE-2024-9632) that could be exploited for privilege escalation on systems where the X server runs with root permissions, as well as for remote code execution in configurations that use X11 session redirection via SSH.

The issue is caused by a buffer overflow in the _XkbSetCompatMap() function that occurs when attempting to resize the sym_interpret buffer during the handling of a specially formatted bitmap. Due to an error in setting the new size, the change only affected the num_si value, leaving the size_si value unchanged. This issue has been present since the release of xorg-server-1.1.1, which was published in 2006.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster