A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Name | Vendor | Start Version | End Version |
---|---|---|---|
X_server | X.org | * | 1.20.10 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | xorg-x11-server-0:1.20.4-15.el7_9 | * |
Red Hat Enterprise Linux 8 | RedHat | egl-wayland-0:1.1.5-3.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | libdrm-0:2.4.103-1.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | libglvnd-1:1.3.2-1.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | libinput-0:1.16.3-1.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | libwacom-0:1.6-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | libX11-0:1.6.8-4.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | mesa-0:20.3.3-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | xorg-x11-drivers-0:7.7-30.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | xorg-x11-server-0:1.20.10-1.el8 | * |
Xorg | Ubuntu | trusty | * |
Xorg-server | Ubuntu | bionic | * |
Xorg-server | Ubuntu | devel | * |
Xorg-server | Ubuntu | focal | * |
Xorg-server | Ubuntu | groovy | * |
Xorg-server | Ubuntu | trusty | * |
Xorg-server | Ubuntu | trusty/esm | * |
Xorg-server | Ubuntu | xenial | * |
Xorg-server-hwe-16.04 | Ubuntu | xenial | * |
Xorg-server-hwe-18.04 | Ubuntu | bionic | * |
Xorg-server-lts-utopic | Ubuntu | trusty | * |
Xorg-server-lts-vivid | Ubuntu | trusty | * |
Xorg-server-lts-wily | Ubuntu | trusty | * |
Xorg-server-lts-xenial | Ubuntu | trusty | * |