DescriptionThe authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs788410

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xorg-server (PTS)buster2:1.20.4-1+deb10u4fixed
buster (security)2:1.20.4-1+deb10u8fixed
bullseye (security)2:1.20.11-1+deb11u5fixed
bookworm, sid2:21.1.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xorg-serversourcesqueeze(not affected)
xorg-serversourcewheezy(not affected)


[wheezy] - xorg-server <not-affected> (XWayland not present)
[squeeze] - xorg-server <not-affected> (XWayland not present)
Patch 1/3:
Patch 2/3:
Patch 3/3:

Search for package or bug name: Reporting problems