DEBIAN-CVE-2024-9632

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2024-9632
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-9632.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2024-9632
Upstream
Published
2024-10-30T08:15:04Z
Modified
2025-09-19T07:34:21.495047Z
Summary
[none]
Details

A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.

References

Affected packages

Debian:11

xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.20.11-1+deb11u14

Affected versions

2:1.*

2:1.20.11-1
2:1.20.11-1+deb11u1
2:1.20.11-1+deb11u2
2:1.20.11-1+deb11u3
2:1.20.11-1+deb11u4
2:1.20.11-1+deb11u5
2:1.20.11-1+deb11u6
2:1.20.11-1+deb11u7
2:1.20.11-1+deb11u8
2:1.20.11-1+deb11u9
2:1.20.11-1+deb11u10
2:1.20.11-1+deb11u11
2:1.20.11-1+deb11u12
2:1.20.11-1+deb11u13

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12

xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.1.7-3+deb12u8

Affected versions

2:21.*

2:21.1.7-3
2:21.1.7-3+deb12u1
2:21.1.7-3+deb12u2
2:21.1.7-3+deb12u3
2:21.1.7-3+deb12u4
2:21.1.7-3+deb12u5
2:21.1.7-3+deb12u6
2:21.1.7-3+deb12u7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13

xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.1.13-3.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

xwayland

Package

Name
xwayland
Purl
pkg:deb/debian/xwayland?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:24.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14

xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.1.13-3.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

xwayland

Package

Name
xwayland
Purl
pkg:deb/debian/xwayland?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:24.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}