X.Org Server 21.1.12 Update Addressing 4 Vulnerabilities

The corrective releases of X.Org Server 21.1.12 and the DDX component (Device-Dependent X) xwayland 23.2.5 have been published, enabling the launch of X.Org Server for running X11 applications in Wayland-based environments. The new version of X.Org Server addresses 4 vulnerabilities. One vulnerability can be exploited to escalate privileges in systems where the X server runs with root privileges, as well as for remote code execution in configurations where session redirection for X11 is accessed using SSH.

The other three vulnerabilities could lead to memory content leakage server or to crashes. These three vulnerabilities are exploited through the use of a different byte order on the client-side than on the server. Consequently, the new release introduces the option to block client connections from systems with a different byte order. This can be disabled using the configuration parameter "AllowByteSwappedClients" or the command line option "+byteswappedclients."

Changing the default value provides protection against potentially undiscovered vulnerabilities that manipulate byte order. The essence of such vulnerabilities is that changing the byte order for data of a certain size can lead to their incorrect interpretation and reading or writing into memory with a size exceeding the allocated buffer.

By default, support for clients with a different byte order is still maintained, despite the fact that, in practice, byte order conversion has recently been used exceedingly rarely, as workstations running the X server are typically equipped with little-endian (from least significant to most significant byte) processors, and connecting to them X clients with a big-endian order, such as the s390x platform (IBM zSystems), is quite rare.

Identified issues:

  • CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 — reading data from out-of-bounds through manipulation of the ProcXIGetSelectedEvents, ProcXIPassiveGrabDevice, and ProcAppleDRICreatePixmap functions, which utilize a field sized without consideration of byte order in the value passed by the client. Consequently, when there are differences in byte order between the client and server, the functions return more data to the client. The first two issues manifest starting from the release of xorg-server-1.7.0 (2009), while the third appears starting from xorg-server-1.15.0 (2012).
  • CVE-2024-31083 — accessing already freed memory (User-after-free) in the ProcRenderAddGlyphs function, which calls the AllocateGlyph() function to save new glyphs passed by the client. The AllocateGlyph() function returns a new glyph with a zero reference count (refcount=0), and re-referencing the glyph does not increase the reference count, causing the glyph_new array to potentially contain multiple entries pointing to one glyph without a reference count. When ProcRenderAddGlyphs() frees the memory allocated for the glyph, an extra pointer instance to the glyph remains in the array, which has already been freed. This issue occurs in the X.Org Server and does not affect xwayland.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster