Logo
vulnerabilityCVE-2024-21886
Name
CVE-2024-21886
Source
NVD ( link)Debian ( link)
Description
A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in some circumstances, remote code execution in SSH X11 forwarding environments.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
xwayland
Not Affected

Vulnerability Ratings#


7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
24.1.12
Not Affected
buildroot
master
24.1.12
Not Affected
yocto
kirkstone
22.1.8
Patched
yocto
scarthgap
23.2.5
Not Affected

Resolved with patches#


xwayland (yocto:kirkstone)

#
Title
Author
Resolve
1
Xi: do not keep linked list pointer during recursion
=?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= <jexposit@redhat.com>
CVE-2024-21886
2
dix: when disabling a master, float disabled slaved devices
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2024-21886