CVE-2024-0409

HIGH EPSS 27.5%
Published Jan 18, 20242y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Jan 18, 2024 2y ago
Last Modified Jun 17, 2026 1w ago

Description

A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
27.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 15

VendorProductVersionRange
tigervnctigervnc* <1.13.1
x.orgx_server* <21.1.11
x.orgxwayland* <23.2.4
fedoraprojectfedora39any
redhatenterprise_linux6.0any
redhatenterprise_linux7.0any
redhatenterprise_linux8.0any
redhatenterprise_linux9.0any
redhatenterprise_linux_desktop7.0any
redhatenterprise_linux_for_ibm_z_systems7.0any
redhatenterprise_linux_for_power_big_endian7.0any
redhatenterprise_linux_for_power_little_endian7.0any
redhatenterprise_linux_for_scientific_computing7.0any
redhatenterprise_linux_server7.0any
redhatenterprise_linux_workstation7.0any

References 13

  • access.redhat.com https://access.redhat.com/errata/RHSA-2024:0320
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2024:2169
  • access.redhat.com https://access.redhat.com/errata/RHSA-2024:2170
  • access.redhat.com https://access.redhat.com/errata/RHSA-2024:2995
  • access.redhat.com https://access.redhat.com/errata/RHSA-2024:2996
  • access.redhat.com https://access.redhat.com/security/cve/CVE-2024-0409
    Third Party Advisory
  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2257690
    Issue TrackingThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2024/01/msg00016.html
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5J4H7CH565ALSZZYKOJFYDA5KFLG6NUK/
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EJBMCWQ54R6ZL3MYU2D2JBW6JMZL7BQW/
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IZ75X54CN4IFYMIV7OK3JVZ57FHQIGIC/
  • security.gentoo.org https://security.gentoo.org/glsa/202401-30
  • security.netapp.com https://security.netapp.com/advisory/ntap-20240307-0006/

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.