ALAS-2024-756


Amazon Linux 2023 Security Advisory: ALAS-2024-756
Advisory Release Date: 2024-11-13 12:28 Pacific
Advisory Updated Date: 2024-11-14 11:00 Pacific
Severity: Important

Issue Overview:

A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges. (CVE-2024-9632)


Affected Packages:

xorg-x11-server


Issue Correction:
Run dnf update xorg-x11-server --releasever 2023.6.20241111 to update your system.

New Packages:
aarch64:
    xorg-x11-server-common-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-Xephyr-debuginfo-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-debuginfo-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-Xnest-debuginfo-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-Xvfb-debuginfo-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-devel-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-Xvfb-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-Xorg-debuginfo-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-Xorg-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-Xnest-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-Xephyr-21.1.13-5.amzn2023.0.2.aarch64
    xorg-x11-server-debugsource-21.1.13-5.amzn2023.0.2.aarch64

noarch:
    xorg-x11-server-source-21.1.13-5.amzn2023.0.2.noarch

src:
    xorg-x11-server-21.1.13-5.amzn2023.0.2.src

x86_64:
    xorg-x11-server-Xephyr-debuginfo-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-debuginfo-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-common-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-Xephyr-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-Xorg-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-Xvfb-debuginfo-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-Xnest-debuginfo-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-Xorg-debuginfo-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-devel-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-Xvfb-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-Xnest-21.1.13-5.amzn2023.0.2.x86_64
    xorg-x11-server-debugsource-21.1.13-5.amzn2023.0.2.x86_64