USN-6587-3: X.Org X Server regression
USN-6587-1 fixed vulnerabilities in X.Org X Server. The fix was incomplete resulting in a possible regression. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled memory when processing the DeviceFocusEvent and ProcXIQueryPointer APIs. An attacker could possibly use this issue to cause the X Server to crash, obtain sensitive information, or execute arbitrary code. (CVE-2023-6816) Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled reattaching to a different master device. An attacker could use this issue to cause the X Server to crash, leading to a denial of service, or possibly execute arbitrary code. (CVE-2024-0229) Olivier Fourdan and Donn Seeley discovered that the X.Org X Server incorrectly labeled GLX PBuffers when used with SELinux. An attacker could use this issue to cause the X Server to crash, leading to a denial of service. (CVE-2024-0408) Olivier Fourdan discovered that the X.Org X Server incorrectly handled the curser code when used with SELinux. An attacker could use this issue to cause the X Server to crash, leading to a denial of service. (CVE-2024-0409) Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled memory when processing the XISendDeviceHierarchyEvent API. An attacker could possibly use this issue to cause the X Server to crash, or execute arbitrary code. (CVE-2024-21885) Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled devices being disabled. An attacker could possibly use this issue to cause the X Server to crash, or execute arbitrary code. (CVE-2024-21886)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6587-3?
The severity of USN-6587-3 is classified as high due to potential security impacts in X.Org X Server.
How do I fix USN-6587-3?
To fix USN-6587-3, upgrade to the recommended package versions specified for your Ubuntu release.
What vulnerabilities does USN-6587-3 address?
USN-6587-3 addresses issues related to memory handling in X.Org X Server that could lead to regressions.
Who discovered the original vulnerabilities addressed in USN-6587-3?
The original vulnerabilities addressed in USN-6587-3 were discovered by Jan-Niklas Sohn.
Which versions of Ubuntu are affected by USN-6587-3?
USN-6587-3 affects specific package versions on Ubuntu 20.04, 22.04, and 23.10.