yocto ▾
›
master ▾
›
vulnerability
›
CVE-2024-21886
Component Overview
Vulnerability Overview
Name
CVE-2024-21886
Source
NVD (
link
)
Debian (
link
)
Description
A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in some circumstances, remote code execution in SSH X11 forwarding environments.
CWEs
CWE-122
Published Date
Feb 28, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
xwayland
Not Affected
Vulnerability Ratings
#
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
xwayland
buildroot
2025.02.x
24.1.12
Not Affected
xwayland
buildroot
master
24.1.12
Not Affected
xwayland
yocto
kirkstone
22.1.8
Patched
xwayland
yocto
scarthgap
23.2.5
Not Affected
Resolved with patches
#
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
Xi: do not keep linked list pointer during recursion
=?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= <jexposit@redhat.com>
CVE-2024-21886
2
dix: when disabling a master, float disabled slaved devices
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2024-21886