Name
CVE-2024-0409
Description
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2024:0320Third Party Advisory
https://access.redhat.com/security/cve/CVE-2024-0409Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2257690Issue Tracking
https://access.redhat.com/errata/RHSA-2024:0320Third Party Advisory
https://access.redhat.com/security/cve/CVE-2024-0409Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2257690Issue Tracking
Analysis#
Vulnerability Ratings#
7.8
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
xserver-xorg (yocto:kirkstone)
#
Title
Author
Resolve
1
ephyr,xwayland: Use the proper private key for cursor
Olivier Fourdan <ofourdan@redhat.com>
CVE-2024-0409
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
ephyr,xwayland: Use the proper private key for cursor
Olivier Fourdan <ofourdan@redhat.com>
CVE-2024-0409