PT-2021-5837 · Xorg+10 · Xorg-X11-Server+10

Jan-Niklas Sohn

·

Published

2021-12-14

·

Updated

2024-06-15

·

CVE-2021-4009

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xorg-x11-server versions before 21.1.2 xorg-x11-server versions before 1.20.14
Description A flaw was found in the SProcXFixesCreatePointerBarrier function, which can cause an out-of-bounds access. This issue poses a threat to data confidentiality and integrity, as well as system availability. The vulnerability can be exploited to gain access to confidential data, disrupt data integrity, and cause a denial of service.
Recommendations For xorg-x11-server versions before 21.1.2, update to version 21.1.2 or later. For xorg-x11-server versions before 1.20.14, update to version 1.20.14 or later. As a temporary workaround, consider disabling the SProcXFixesCreatePointerBarrier function until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1917
ALT-PU-2021-3534
ALT-PU-2021-3544
ALT-PU-2021-3623
ALT-PU-2022-1458
ALT-PU-2023-7278
ALT-PU-2024-3261
BDU:2022-00347
CESA-2022_0003
CESA-2022_1917
CVE-2021-4009
DLA-2869-1
DSA-5027-1
MGASA-2021-0573
OESA-2021-1468
OESA-2022-1949
OPENSUSE-SU-2021:1606-1
OPENSUSE-SU-2021:4136-1
OPENSUSE-SU-2021_1606-1
OPENSUSE-SU-2021_4136-1
OPENSUSE-SU-2021_4136-2
OPENSUSE-SU-2024:11685-1
OPENSUSE-SU-2024:11699-1
RHSA-2022:0003
RHSA-2022:1917
RHSA-2022_0003
RHSA-2022_1917
RLSA-2022:1917
SUSE-SU-2021:4119-1
SUSE-SU-2021:4120-1
SUSE-SU-2021:4121-1
SUSE-SU-2021:4122-1
SUSE-SU-2021:4124-1
SUSE-SU-2021:4136-1
SUSE-SU-2021:4136-2
SUSE-SU-2021_4119-1
SUSE-SU-2021_4120-1
SUSE-SU-2021_4121-1
SUSE-SU-2021_4122-1
SUSE-SU-2021_4124-1
SUSE-SU-2021_4136-1
USN-5193-1
USN-5193-2
USN-5193-3
ZDI-21-1548

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Xorg-X11-Server