alsa-2022:1917
Vulnerability from osv_almalinux
X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon. Xwayland is an X server for running X clients under Wayland. The following packages have been upgraded to a later upstream version: xorg-x11-server-Xwayland (21.1.3). (BZ#2015842) Security Fix(es): * xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access (CVE-2021-4008) * xorg-x11-server: SProcXFixesCreatePointerBarrier out-of-bounds access (CVE-2021-4009) * xorg-x11-server: SProcScreenSaverSuspend out-of-bounds access (CVE-2021-4010) * xorg-x11-server: SwapCreateRegister out-of-bounds access (CVE-2021-4011) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-Xdmx"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-Xephyr"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-Xnest"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-Xorg"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-Xvfb"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-Xwayland"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "21.1.3-2.el8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-common"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8_6.2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "xorg-x11-server-source"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.11-5.el8"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.\nXwayland is an X server for running X clients under Wayland.\nThe following packages have been upgraded to a later upstream version: xorg-x11-server-Xwayland (21.1.3). (BZ#2015842)\nSecurity Fix(es):\n* xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access (CVE-2021-4008)\n* xorg-x11-server: SProcXFixesCreatePointerBarrier out-of-bounds access (CVE-2021-4009)\n* xorg-x11-server: SProcScreenSaverSuspend out-of-bounds access (CVE-2021-4010)\n* xorg-x11-server: SwapCreateRegister out-of-bounds access (CVE-2021-4011)\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.",
"id": "ALSA-2022:1917",
"modified": "2022-06-30T13:08:08Z",
"published": "2022-05-10T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2022:1917"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2021-4008"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2021-4009"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2021-4010"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2021-4011"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2026059"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2026072"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2026073"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2026074"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/8/ALSA-2022-1917.html"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2021-4008"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2021-4009"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2021-4010"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2021-4011"
}
],
"related": [
"CVE-2021-4008",
"CVE-2021-4009",
"CVE-2021-4010",
"CVE-2021-4011"
],
"summary": "Moderate: xorg-x11-server and xorg-x11-server-Xwayland security update"
}
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.