Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| X_server | X.org | * | 21.2.24 (excluding) |
| Xwayland | X.org | * | 24.1.13 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.3 | * |
| Red Hat Enterprise Linux 8 | RedHat | xorg-x11-server-0:1.20.11-28.el8_10.3 | * |
| Red Hat Enterprise Linux 8 | RedHat | xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.3 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | xorg-x11-server-0:1.20.10-5.el8_4.1 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | xorg-x11-server-0:1.20.10-5.el8_4.1 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | xorg-x11-server-0:1.20.11-8.el8_6.1 | * |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | RedHat | xorg-x11-server-0:1.20.11-8.el8_6.1 | * |
| Red Hat Enterprise Linux 9 | RedHat | xorg-x11-server-0:1.20.11-34.el9_8.3 | * |
| Red Hat Enterprise Linux 9 | RedHat | xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | xorg-x11-server-0:1.20.11-21.el9_2.1 | * |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | RedHat | xorg-x11-server-0:1.20.11-29.el9_4.1 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | xorg-x11-server-0:1.20.11-34.el9_6.1 | * |
| Xorg-server | Ubuntu | questing | * |
| Xwayland | Ubuntu | questing | * |