NA

CVE-2024-31080

Published: 04/04/2024 Updated: 24/05/2024

Vulnerability Summary

A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an malicious user to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.

Vendor Advisories

A heap-based buffer over-read vulnerability was found in the Xorg server's ProcXIGetSelectedEvents() function This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness This vulnerability could be exploit ...
A heap-based buffer over-read vulnerability was found in the Xorg server's ProcXIGetSelectedEvents() function This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness This vulnerability could be exploit ...

Mailing Lists

-------- Forwarded Message -------- Subject: Re: XOrg Security Advisory: Issues in XOrg X server prior to 21112 and Xwayland prior to 2325 Date: Fri, 12 Apr 2024 10:41:28 -0700 From: Alan Coopersmith <alancoopersmith () oracle com> To: xorg-announce () lists x org CC: xorg () lists x org <xorg () lists x org> The fix we provided ...
-------- Forwarded Message -------- Date: Wed, 3 Apr 2024 11:43:34 -0700 From: Alan Coopersmith <alancoopersmith () oracle com> To: xorg-announce () lists x org CC: xorg () lists x org <xorg () lists x org> XOrg Security Advisory: April 3, 2024 Issues in XOrg X server prior to 21112 and Xwayland prior to 2325 ================= ...