A corrective release of X.Org Server 21.1.13 has been published, which addresses a bug introduced while fixing the vulnerability CVE-2024-31083 in the previous version. The fix led to a double call of the free() function in certain situations. Despite the presence of this error, which is typically viewed as a "double-free" class vulnerability, the developers at X.Org have not explicitly marked it as a vulnerability — it is only mentioned that it leads to a crash of the X server.
A similar issue has been fixed in the DDX component xwayland 23.2.6, which allows the X.Org Server to run X11 applications in Wayland-based environments.
Source: opennet.ru
