Name | CVE-2024-0408 |
Description | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object that was never labeled and crash because the SID is NULL. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-3721-1, DSA-5603-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
xorg-server (PTS) | bullseye (security), bullseye | 2:1.20.11-1+deb11u13 | fixed |
bookworm, bookworm (security) | 2:21.1.7-3+deb12u7 | fixed | |
sid, trixie | 2:21.1.13-2 | fixed | |
xwayland (PTS) | bookworm | 2:22.1.9-1 | vulnerable |
sid, trixie | 2:24.1.2-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
xorg-server | source | buster | 2:1.20.4-1+deb10u13 | DLA-3721-1 | ||
xorg-server | source | bullseye | 2:1.20.11-1+deb11u11 | DSA-5603-1 | ||
xorg-server | source | bookworm | 2:21.1.7-3+deb12u5 | DSA-5603-1 | ||
xorg-server | source | (unstable) | 2:21.1.11-1 | |||
xwayland | source | (unstable) | 2:23.2.4-1 |
[bookworm] - xwayland <no-dsa> (Minor issue; Xwayland shouldn't be running as root)
https://lists.x.org/archives/xorg/2024-January/061525.html
https://gitlab.freedesktop.org/xorg/xserver/-/commit/e5e8586a12a3ec915673edffa10dc8fe5e15dac3