USN-5193-1: X.Org X Server vulnerabilities
Published Dec 14, 2021
·Updated
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled certain inputs. An attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly execute arbitrary code and escalate privileges.
Affected Software
14 affected componentsFixes available
All of the following
ubuntu/xserver-xorg-core<2:1.20.13-1ubuntu1.1
2:1.20.13-1ubuntu1.1
Ubuntu Ubuntu=21.10
All of the following
ubuntu/xwayland<2:21.1.2-0ubuntu1.1
2:21.1.2-0ubuntu1.1
Ubuntu Ubuntu=21.10
All of the following
ubuntu/xserver-xorg-core<2:1.20.11-1ubuntu1.2
2:1.20.11-1ubuntu1.2
Ubuntu Ubuntu=21.04
All of the following
ubuntu/xwayland<2:21.1.1-0ubuntu1.1
2:21.1.1-0ubuntu1.1
Ubuntu Ubuntu=21.04
All of the following
ubuntu/xserver-xorg-core<2:1.20.13-1ubuntu1~20.04.2
2:1.20.13-1ubuntu1~20.04.2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/xserver-xorg-core<2:1.19.6-1ubuntu4.10
2:1.19.6-1ubuntu4.10
Ubuntu Ubuntu=18.04
All of the following
ubuntu/xserver-xorg-core-hwe-18.04<2:1.20.8-2ubuntu2.2~18.04.6
2:1.20.8-2ubuntu2.2~18.04.6
Ubuntu Ubuntu=18.04
Event History
Dec 14, 2021
Advisory Published
via Ubuntu·12:00 AM
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for the X.Org X Server vulnerability?
The vulnerability ID is CVE-2021-4008, CVE-2021-4010, and CVE-2021-4011.
2
What is the severity of the X.Org X Server vulnerability?
The severity of the vulnerability is not specified.
3
How does the X.Org X Server vulnerability affect Ubuntu?
The X.Org X Server vulnerability affects Ubuntu versions 21.10, 21.04, 20.04, and 18.04.
4
How can an attacker exploit the X.Org X Server vulnerability?
An attacker can exploit the X.Org X Server vulnerability to cause a denial of service or execute arbitrary code.
5
What is the remedy for the X.Org X Server vulnerability?
The remedy for the X.Org X Server vulnerability is to update the affected packages to the specified versions.