跳转到帖子

Alma Linux: CVE-2024-31083: Moderate: xorg-x11-server security update (Multiple Advisories)

recommended_posts

发布于
  • Members

Alma Linux: CVE-2024-31083: Moderate: xorg-x11-server security update (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
04/05/2024
Created
04/30/2024
Added
04/30/2024
Modified
11/19/2024

Description

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

Solution(s)

  • alma-upgrade-tigervnc
  • alma-upgrade-tigervnc-icons
  • alma-upgrade-tigervnc-license
  • alma-upgrade-tigervnc-selinux
  • alma-upgrade-tigervnc-server
  • alma-upgrade-tigervnc-server-minimal
  • alma-upgrade-tigervnc-server-module
  • alma-upgrade-xorg-x11-server-common
  • alma-upgrade-xorg-x11-server-devel
  • alma-upgrade-xorg-x11-server-source
  • alma-upgrade-xorg-x11-server-xdmx
  • alma-upgrade-xorg-x11-server-xephyr
  • alma-upgrade-xorg-x11-server-xnest
  • alma-upgrade-xorg-x11-server-xorg
  • alma-upgrade-xorg-x11-server-xvfb
  • alma-upgrade-xorg-x11-server-xwayland
  • alma-upgrade-xorg-x11-server-xwayland-devel

References

  • https://attackerkb.com/topics/cve-2024-31083
  • CVE - 2024-31083
  • https://errata.almalinux.org/8/ALSA-2024-2037.html
  • https://errata.almalinux.org/8/ALSA-2024-3258.html
  • https://errata.almalinux.org/8/ALSA-2024-3261.html
  • https://errata.almalinux.org/8/ALSA-2024-3343.html
  • https://errata.almalinux.org/9/ALSA-2024-2616.html
  • https://errata.almalinux.org/9/ALSA-2024-9093.html
  • https://errata.almalinux.org/9/ALSA-2024-9122.html
View more
  • 查看数 709
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…