7.2
CVSSv2

CVE-2021-4009

Published: 17/12/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A flaw was found in xorg-x11-server in versions prior to 21.1.2 and prior to 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

x.org x server

x.org x server 21.1.1

x.org x server 21.1.0

fedoraproject fedora 34

fedoraproject fedora 35

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Synopsis Moderate: xorg-x11-server and xorg-x11-server-Xwayland security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for xorg-x11-server and xorg-x11-server-Xwayland is now available for Red Hat Enterp ...
Jan-Niklas Sohn discovered that multiple input validation failures in X server extensions of the Xorg X server may result in privilege escalation if the X server is running privileged For the oldstable distribution (buster), these problems have been fixed in version 2:1204-1+deb10u4 For the stable distribution (bullseye), these problems have b ...
A flaw was found in the Xorg-x11-server An out-of-bounds access issue can occur in the SProcRenderCompositeGlyphs function due to improper validation of the request length (CVE-2021-4008) A flaw was found in xorg-x11-server An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function (CVE-2021-4009) A flaw was found in xorg ...
A security issue has been found in XOrg before version 2112 The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SS ...
A flaw was found in the Xorg-x11-server An out-of-bounds access issue can occur in the SProcRenderCompositeGlyphs function due to improper validation of the request length (CVE-2021-4008) A flaw was found in xorg-x11-server An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function (CVE-2021-4009) A flaw was found in xorg ...