A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | tigervnc | 2024-11-08 18:01 | ALAS2-2024-2691 |
Amazon Linux 2 - Core | xorg-x11-server | 2024-11-08 18:01 | ALAS2-2024-2692 |
Amazon Linux 2023 | xorg-x11-server | 2024-11-13 12:28 | ALAS2023-2024-756 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
NVD | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |