PT-2024-1242 · X.Org+9 · Xwayland+10

Patrick Del Bello

·

Published

2024-01-16

·

Updated

2025-09-15

·

CVE-2024-0408

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions X.Org server versions prior to 21.1.11 Xwayland versions prior to 23.2.4
Description A flaw was found in the X.Org server, specifically in the GLX PBuffer code, which does not call the XACE hook when creating the buffer, leaving it unlabeled. This can cause the XSELINUX code to crash when trying to access the buffer, as the SID is NULL. The issue is related to pointer dereference errors in the GLX PBuffer Handler component of the X Window System X.Org Server. Exploitation of this issue can allow an attacker to cause a denial of service.
Recommendations For X.Org server versions prior to 21.1.11, update to version 21.1.11 or later to resolve the issue. For Xwayland versions prior to 23.2.4, update to version 23.2.4 or later to resolve the issue. As a temporary workaround, consider disabling the SELinux xserver object manager to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2169
ALSA-2024:2170
ALSA-2024:2995
ALSA-2024:2996
ALT-PU-2024-1181
ALT-PU-2024-1182
ALT-PU-2024-1183
ALT-PU-2024-1936
ALT-PU-2024-3261
ALT-PU-2024-3843
ALT-PU-2024-4743
ALT-PU-2024-4745
ALT-PU-2024-5972
ALT-PU-2025-11601
AZL-33352
AZL-35354
AZL-44691
BDU:2024-00638
CESA-2024_0320
CESA-2024_2995
CESA-2024_2996
CVE-2024-0408
DLA-3721-1
DSA-5603-1
INFSA-2024_2169
INFSA-2024_2170
INFSA-2024_2995
INFSA-2024_2996
MGASA-2024-0022
OESA-2024-1102
OESA-2024-1548
OESA-2024-1556
OESA-2024-1557
OPENSUSE-SU-2024:13597-1
OPENSUSE-SU-2024:13598-1
OPENSUSE-SU-2024_0212-1
OPENSUSE-SU-2024_0249-1
RHSA-2024:0320
RHSA-2024:2169
RHSA-2024:2170
RHSA-2024:2995
RHSA-2024:2996
RHSA-2024_0320
RHSA-2024_2169
RHSA-2024_2170
RHSA-2024_2995
RHSA-2024_2996
ROSA-SA-2024-2351
ROSA-SA-2025-2575
ROSA-SA-2025-2576
SUSE-SU-2024:0165-1
SUSE-SU-2024:0212-1
SUSE-SU-2024:0236-1
SUSE-SU-2024:0249-1
SUSE-SU-2024:0251-1
SUSE-SU-2024:0252-1
SUSE-SU-2024_0236-1
SUSE-SU-2024_0249-1
SUSE-SU-2024_0251-1
SUSE-SU-2024_0252-1
USN-6587-1
USN-6587-2
USN-6587-3
USN-6587-4
USN-6587-5

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Suse
Ubuntu
X.Org Server
Xwayland