Record summary

CVE-2024-21885 has a selected CVSS score of 7.8 (high).

Description

A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array length when certain new device IDs are added to the xXIHierarchyInfo struct. This can trigger a heap buffer overflow condition, which may lead to an application crash or remote code execution in SSH X11 forwarding environments.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 26, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 22
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 6

Browse Red Hat / Red Hat Enterprise Linux 6xorg-x11-server

Default status: unknown

CVE ListVersion data not supplied

Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION

Browse Red Hat / Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervnc

Default status: affected

CVE List0:1.1.0-25.el6_10.13 to < *unaffected

Red Hat Enterprise Linux 7

Browse Red Hat / Red Hat Enterprise Linux 7tigervnc

Default status: affected

CVE List0:1.8.0-31.el7_9 to < *unaffected

Red Hat Enterprise Linux 7

Browse Red Hat / Red Hat Enterprise Linux 7xorg-x11-server

Default status: affected

CVE List0:1.20.4-27.el7_9 to < *unaffected

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8tigervnc

Default status: affected

CVE List0:1.13.1-2.el8_9.7 to < *unaffected

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8xorg-x11-server

Default status: affected

CVE List0:1.20.11-22.el8 to < *unaffected

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8xorg-x11-server-Xwayland

Default status: affected

CVE List0:21.1.3-15.el8 to < *unaffected

Red Hat Enterprise Linux 8.2 Advanced Update Support

Browse Red Hat / Red Hat Enterprise Linux 8.2 Advanced Update Supporttigervnc

Default status: affected

CVE List0:1.9.0-15.el8_2.9 to < *unaffected

Red Hat Enterprise Linux 8.2 Telecommunications Update Service

Browse Red Hat / Red Hat Enterprise Linux 8.2 Telecommunications Update Servicetigervnc

Default status: affected

CVE List0:1.9.0-15.el8_2.9 to < *unaffected

Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions

Browse Red Hat / Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionstigervnc

Default status: affected

CVE List0:1.9.0-15.el8_2.9 to < *unaffected

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

Browse Red Hat / Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supporttigervnc

Default status: affected

CVE List0:1.11.0-8.el8_4.8 to < *unaffected

Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Browse Red Hat / Red Hat Enterprise Linux 8.4 Telecommunications Update Servicetigervnc

Default status: affected

CVE List0:1.11.0-8.el8_4.8 to < *unaffected

References

Showing 12 of 23