CVE-2024-9632

Name
CVE-2024-9632
Description
A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2024-9632
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2317233
vendor-advisory https://access.redhat.com/errata/RHSA-2024:8798
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:10090
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9540
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9579
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9601
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9690
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9816
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9818
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9819
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9820
secalert@redhat.com https://access.redhat.com/errata/RHSA-2024:9901
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:7163
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:7165
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2024/Oct/20
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2024/10/29/2
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2024/10/msg00031.html
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:7458

Match rules

CPE URI Source package Min version Max version
cpe:/a:redhat:enterprise_linux:8::appstream shopxo >= 0:1.20.11-25.el8_10 < *
cpe:/a:redhat:enterprise_linux:8::appstream shopxo >= 0:21.1.3-17.el8_10 < *

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
xwayland edge-community 24.1.4-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland 3.20-community 24.1.4-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xorg-server edge-community 21.1.14-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
xorg-server 3.20-community 21.1.14-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
xorg-server 3.21-community 21.1.14-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
xwayland 3.21-community 24.1.4-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed