CVE-2024-0229
09.02.2024, 07:16
An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution in SSH X11 forwarding environments.Enginsight
| Vendor | Product | Version |
|---|---|---|
| x.org | x_server | 𝑥 < 21.1.11 |
| x.org | xwayland | 𝑥 < 23.2.4 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux_aus | 8.2 |
| redhat | enterprise_linux_aus | 8.4 |
| redhat | enterprise_linux_eus | 8.6 |
| redhat | enterprise_linux_eus | 8.8 |
| redhat | enterprise_linux_eus | 9.0 |
| redhat | enterprise_linux_eus | 9.2 |
| redhat | enterprise_linux_tus | 8.2 |
| redhat | enterprise_linux_tus | 8.4 |
| redhat | enterprise_linux_update_services_for_sap_solutions | 8.2 |
| redhat | enterprise_linux_update_services_for_sap_solutions | 8.4 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-server |
| ||||||||||||||||
| xwayland |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg |
| ||||||||||||||||||||||
| xwayland |
| ||||||||||||||||||||||
| xorg-server-hwe-16.04 |
| ||||||||||||||||||||||
| xorg-server-hwe-18.04 |
| ||||||||||||||||||||||
| xorg-hwe-16.04 |
| ||||||||||||||||||||||
| xorg-hwe-18.04 |
| ||||||||||||||||||||||
| xorg-server-lts-utopic |
| ||||||||||||||||||||||
| xorg-server-lts-vivid |
| ||||||||||||||||||||||
| xorg-server-lts-wily |
| ||||||||||||||||||||||
| xorg-server-lts-xenial |
| ||||||||||||||||||||||
| xorg-server |
|
Common Weakness Enumeration
References