First published: Tue Jan 16 2024(Updated: )
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled memory when processing the DeviceFocusEvent and ProcXIQueryPointer APIs. An attacker could possibly use this issue to cause the X Server to crash, obtain sensitive information, or execute arbitrary code. (CVE-2023-6816) Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled reattaching to a different master device. An attacker could use this issue to cause the X Server to crash, leading to a denial of service, or possibly execute arbitrary code. (CVE-2024-0229) Olivier Fourdan and Donn Seeley discovered that the X.Org X Server incorrectly labeled GLX PBuffers when used with SELinux. An attacker could use this issue to cause the X Server to crash, leading to a denial of service. (CVE-2024-0408) Olivier Fourdan discovered that the X.Org X Server incorrectly handled the curser code when used with SELinux. An attacker could use this issue to cause the X Server to crash, leading to a denial of service. (CVE-2024-0409) Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled memory when processing the XISendDeviceHierarchyEvent API. An attacker could possibly use this issue to cause the X Server to crash, or execute arbitrary code. (CVE-2024-21885) Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled devices being disabled. An attacker could possibly use this issue to cause the X Server to crash, or execute arbitrary code. (CVE-2024-21886)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/xserver-xorg-core | <2:21.1.7-3ubuntu2.6 | 2:21.1.7-3ubuntu2.6 |
Ubuntu Ubuntu | =23.10 | |
All of | ||
ubuntu/xwayland | <2:23.2.0-1ubuntu0.4 | 2:23.2.0-1ubuntu0.4 |
Ubuntu Ubuntu | =23.10 | |
All of | ||
ubuntu/xserver-xorg-core | <2:21.1.7-1ubuntu3.6 | 2:21.1.7-1ubuntu3.6 |
Ubuntu Ubuntu | =23.04 | |
All of | ||
ubuntu/xwayland | <2:22.1.8-1ubuntu1.4 | 2:22.1.8-1ubuntu1.4 |
Ubuntu Ubuntu | =23.04 | |
All of | ||
ubuntu/xserver-xorg-core | <2:21.1.4-2ubuntu1.7~22.04.7 | 2:21.1.4-2ubuntu1.7~22.04.7 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/xwayland | <2:22.1.1-1ubuntu0.10 | 2:22.1.1-1ubuntu0.10 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/xserver-xorg-core | <2:1.20.13-1ubuntu1~20.04.14 | 2:1.20.13-1ubuntu1~20.04.14 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/xwayland | <2:1.20.13-1ubuntu1~20.04.14 | 2:1.20.13-1ubuntu1~20.04.14 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)