Heap Buffer Overflow Vulnerability in X.Org Server
CVE-2024-21885
7.8HIGH
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 28 February 2024
Summary
A flaw has been identified in the X.Org Server affecting the XISendDeviceHierarchyEvent function, which handles new device IDs. This flaw allows for the potential exceeding of allocated array lengths within the xXIHierarchyInfo struct, leading to a heap buffer overflow condition. Such overflow can result in critical issues like application crashes or the execution of arbitrary code within SSH X11 forwarding environments, posing significant security risks to affected systems.
Affected Version(s)
Red Hat Enterprise Linux 7 0:1.20.4-27.el7_9
Red Hat Enterprise Linux 7 0:1.8.0-31.el7_9
Red Hat Enterprise Linux 8 0:1.13.1-2.el8_9.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Red Hat would like to thank Jan-Niklas Sohn (Trend Micro Zero Day Initiative) for reporting this issue.