Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-44382.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-44382
Upstream
Published
2024-04-05T12:15:37Z
Modified
2026-04-01T05:15:35.461344Z
Summary
CVE-2024-31083 affecting package xorg-x11-server 1.20.10-6
Details

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

References

Affected packages

Azure Linux:3 / xorg-x11-server

Package

Name
xorg-x11-server
Purl
pkg:rpm/azure-linux/xorg-x11-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.20.10-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-44382.json"