NA

CVE-2024-31080

Published: 04/04/2024 Updated: 01/05/2024

Vulnerability Summary

A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an malicious user to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.

Vendor Advisories

A heap-based buffer over-read vulnerability was found in the Xorg server's ProcXIGetSelectedEvents() function This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness This vulnerability could be exploit ...
A heap-based buffer over-read vulnerability was found in the Xorg server's ProcXIGetSelectedEvents() function This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness This vulnerability could be exploit ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Fwd: XOrg Security Advisory: Issues in XOrg X server prior to 21112 and Xwayland prior to 2325 <!--X-Subject-Header-End- ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Fwd: XOrg Security Advisory: Issues in XOrg X server prior to 21112 and Xwayland prior to 2325 <!--X-Subject-Header- ...