CVE Vulnerabilities

CVE-2020-14361

Integer Underflow (Wrap or Wraparound)

Published: Sep 15, 2020 | Modified: Aug 29, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

NameVendorStart VersionEnd Version
X_serverX.org*1.20.9 (excluding)
Red Hat Enterprise Linux 6RedHatxorg-x11-server-0:1.17.4-18.el6_10*
Red Hat Enterprise Linux 7RedHatxorg-x11-server-0:1.20.4-12.el7_9*
Red Hat Enterprise Linux 8RedHategl-wayland-0:1.1.5-3.el8*
Red Hat Enterprise Linux 8RedHatlibdrm-0:2.4.103-1.el8*
Red Hat Enterprise Linux 8RedHatlibglvnd-1:1.3.2-1.el8*
Red Hat Enterprise Linux 8RedHatlibinput-0:1.16.3-1.el8*
Red Hat Enterprise Linux 8RedHatlibwacom-0:1.6-2.el8*
Red Hat Enterprise Linux 8RedHatlibX11-0:1.6.8-4.el8*
Red Hat Enterprise Linux 8RedHatmesa-0:20.3.3-2.el8*
Red Hat Enterprise Linux 8RedHatxorg-x11-drivers-0:7.7-30.el8*
Red Hat Enterprise Linux 8RedHatxorg-x11-server-0:1.20.10-1.el8*
XorgUbuntutrusty*
Xorg-serverUbuntubionic*
Xorg-serverUbuntudevel*
Xorg-serverUbuntuesm-infra-legacy/trusty*
Xorg-serverUbuntuesm-infra/bionic*
Xorg-serverUbuntuesm-infra/focal*
Xorg-serverUbuntuesm-infra/xenial*
Xorg-serverUbuntufocal*
Xorg-serverUbuntutrusty*
Xorg-serverUbuntutrusty/esm*
Xorg-serverUbuntuupstream*
Xorg-serverUbuntuxenial*
Xorg-server-hwe-16.04Ubuntuesm-infra/xenial*
Xorg-server-hwe-16.04Ubuntuupstream*
Xorg-server-hwe-16.04Ubuntuxenial*
Xorg-server-hwe-18.04Ubuntubionic*
Xorg-server-hwe-18.04Ubuntuesm-infra/bionic*
Xorg-server-hwe-18.04Ubuntuupstream*
Xorg-server-lts-utopicUbuntutrusty*
Xorg-server-lts-vividUbuntutrusty*
Xorg-server-lts-wilyUbuntutrusty*
Xorg-server-lts-xenialUbuntutrusty*

References