REDHAT-BUG-2485389: High severity X.Org Foundation xorg-server vulnerability
A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write in DRIGetBuffers/DRIGetBuffersWithFormat.
Any local X client that can connect to the server can trigger this issue. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Components affected: xorg-x11-server, xorg-x11-server-Xwayland Versions affected: xorg-x11-server <= 21.1.22, xorg-x11-server-Xwayland <= 24.1.9
Fixed upstream in xorg-server-21.1.23 and xwayland-24.1.12. Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/339c279514326134b0878fc23ce6e9520440ce7f
Identified by Peter Hutterer, Red Hat. Tracking: PSIRTSUPT-16950.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
xorg-x11-serverto a version that resolves this vulnerability.Fixed in 21.1.23 - Upgrade
Upgrade
xorg-x11-server-Xwaylandto a version that resolves this vulnerability.Fixed in 24.1.12 - Compensating control
Because any local X client that can connect to the server can trigger the issue, restrict network/access to the X server so only trusted clients can connect.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2485389?
The severity of REDHAT-BUG-2485389 is classified as high (7).
How do I fix REDHAT-BUG-2485389?
To fix REDHAT-BUG-2485389, ensure that you update to the latest version of the xorg-server and Xwayland packages provided by the X.Org Foundation.
What causes REDHAT-BUG-2485389?
REDHAT-BUG-2485389 is caused by a client requesting multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft, which can lead to an out-of-bounds heap write.
Who is affected by REDHAT-BUG-2485389?
Any local X client that can connect to the server is potentially affected by REDHAT-BUG-2485389.
What is the potential impact of REDHAT-BUG-2485389?
The potential impact of REDHAT-BUG-2485389 includes the inability to access the server, which may crash the server or allow privilege escalation.