Logo
vulnerabilityCVE-2024-21886
Name
CVE-2024-21886
Source
NVD ( link)Debian ( link)
Description
A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in some circumstances, remote code execution in SSH X11 forwarding environments.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Vulnerability Ratings#


7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
21.1.24
Exploitable
buildroot
master
24.1.13
Exploitable
yocto
kirkstone
22.1.8
Patched
yocto
master
24.1.13
Not Affected
yocto
scarthgap
23.2.5
Exploitable

Resolved with patches#


xwayland (yocto:kirkstone)

#
Title
Author
Resolve
1
Xi: do not keep linked list pointer during recursion
=?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= <jexposit@redhat.com>
CVE-2024-21886
2
dix: when disabling a master, float disabled slaved devices
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2024-21886