PT-2024-1266 · Unknown+12 · X.Org Server+12

Robb Gatica

·

Published

2024-01-16

·

Updated

2025-08-04

·

CVE-2024-21886

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions
X.Org Server versions prior to 21.1.11 Xwayland versions prior to 23.2.4 xorg-server versions prior to 1.20.8-alt12 xorg-server versions prior to 1.20.14-alt11 xorg-xwayland versions prior to 23.1.1-alt4
Description
A heap buffer overflow flaw was discovered in the DisableDevice function within the X.Org server and Xwayland. Successful exploitation of this vulnerability could lead to a denial of service or, in certain scenarios involving SSH X11 forwarding, remote code execution.
Recommendations
Upgrade to X.Org Server version 21.1.11 or later. Upgrade to Xwayland version 23.2.4 or later. Upgrade to xorg-server version 1.20.8-alt12 or later. Upgrade to xorg-server version 1.20.14-alt11 or later. Upgrade to xorg-xwayland version 23.1.1-alt4 or later.

Fix

RCE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2024:0557
ALSA-2024:0607
ALSA-2024:2169
ALSA-2024:2170
ALSA-2024:2995
ALSA-2024:2996
ALT-PU-2024-1181
ALT-PU-2024-1182
ALT-PU-2024-1183
ALT-PU-2024-3261
ALT-PU-2024-4743
ALT-PU-2024-4745
AZL-35404
AZL-44568
BDU:2024-00675
CESA-2024_0320
CESA-2024_0607
CESA-2024_0629
CESA-2024_2995
CESA-2024_2996
CVE-2024-21886
DLA-3721-1
DSA-5603-1
INFSA-2024_2169
INFSA-2024_2170
INFSA-2024_2995
INFSA-2024_2996
MGASA-2024-0022
OESA-2024-1102
OPENSUSE-SU-2024:13597-1
OPENSUSE-SU-2024:13598-1
RHSA-2024:0320
RHSA-2024:0557
RHSA-2024:0558
RHSA-2024:0597
RHSA-2024:0607
RHSA-2024:0614
RHSA-2024:0617
RHSA-2024:0621
RHSA-2024:0626
RHSA-2024:0629
RHSA-2024:2169
RHSA-2024:2170
RHSA-2024:2995
RHSA-2024:2996
RHSA-2024_0320
RHSA-2024_0557
RHSA-2024_0607
RHSA-2024_0629
RHSA-2024_2169
RHSA-2024_2170
RHSA-2024_2995
RHSA-2024_2996
RHSA-2025:12751
RLSA-2024:0607
ROSA-SA-2024-2351
ROSA-SA-2024-2352
ROSA-SA-2025-2575
ROSA-SA-2025-2576
SUSE-SU-2024:0109-1
SUSE-SU-2024:0111-1
SUSE-SU-2024:0114-1
SUSE-SU-2024:0116-1
SUSE-SU-2024:0121-1
SUSE-SU-2024:0165-1
USN-6587-1
USN-6587-2
USN-6587-3
USN-6587-4
USN-6587-5
ZDI-24-119

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
X.Org Server
Xwayland