CVE-2024-31082
published 2024-04-04CVE-2024-31082: A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length…
PriorityP339high7.3CVSS 3.1
AVLACLPRLUINSUCHILAH
EPSS
0.34%
26.3th percentile
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:21.1.7-3+deb12u7 (bookworm) | xorg-server 2:21.1.7-3+deb12u7 (bookworm) |
| msrc | cbl2_xorg-x11-server_1.20.10-11_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_xorg-x11-server_1.20.10-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| x.org | xorg-server | >= 0 < 2:1.20.11-1+deb11u13 | 2:1.20.11-1+deb11u13 |
| x.org | xorg-server | >= 0 < 2:21.1.7-3+deb12u7 | 2:21.1.7-3+deb12u7 |
| x.org | xorg-server | >= 0 < 2:21.1.11-3 | 2:21.1.11-3 |
| x.org | xorg-server | >= 0 < 2:21.1.11-3 | 2:21.1.11-3 |
| x.org | xorg-server | >= 0 < 2:1.20.13-1ubuntu1~20.04.17 | 2:1.20.13-1ubuntu1~20.04.17 |
| x.org | xorg-server | >= 0 < 2:1.20.13-1ubuntu1~20.04.16 | 2:1.20.13-1ubuntu1~20.04.16 |
| x.org | xorg-server | >= 0 < 2:21.1.4-2ubuntu1.7~22.04.10 | 2:21.1.4-2ubuntu1.7~22.04.10 |
| x.org | xorg-server | >= 0 < 2:21.1.4-2ubuntu1.7~22.04.9 | 2:21.1.4-2ubuntu1.7~22.04.9 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.11+esm12 | 2:1.15.1-0ubuntu2.11+esm12 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.11+esm11 | 2:1.15.1-0ubuntu2.11+esm11 |
| x.org | xorg-server | >= 0 < 2:1.18.4-0ubuntu0.12+esm13 | 2:1.18.4-0ubuntu0.12+esm13 |
| x.org | xorg-server | >= 0 < 2:1.18.4-0ubuntu0.12+esm12 | 2:1.18.4-0ubuntu0.12+esm12 |
| x.org | xorg-server | >= 0 < 2:1.19.6-1ubuntu4.15+esm8 | 2:1.19.6-1ubuntu4.15+esm8 |
| x.org | xorg-server | >= 0 < 2:1.19.6-1ubuntu4.15+esm7 | 2:1.19.6-1ubuntu4.15+esm7 |
| x.org | xwayland | >= 0 < 2:22.1.1-1ubuntu0.13 | 2:22.1.1-1ubuntu0.13 |
| x.org | xwayland | >= 0 < 2:22.1.1-1ubuntu0.12 | 2:22.1.1-1ubuntu0.12 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
osv7.3HIGH
vendor_debian7.3HIGH
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server regression
vendor_ubuntu·2024-04-09·CVSS 7.3
CVE-2024-31080 [HIGH] X.Org X Server regression
Title: X.Org X Server regression
Summary: A regression was fixed in X.Org X Server.
USN-6721-1 fixed vulnerabilities in X.Org X Server. That fix was incomplete
resulting in a regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)
It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)
Instructions: After a standard system update you need to restart -APP- to make
all the necessary changes.
Microsoft
Xorg-x11-server: heap buffer overread/data leakage in procappledricreatepixmap
vendor_msrc·2024-04-09·CVSS 7.3
CVE-2024-31082 [HIGH] CWE-126 Xorg-x11-server: heap buffer overread/data leakage in procappledricreatepixmap
Xorg-x11-server: heap buffer overread/data leakage in procappledricreatepixmap
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2024-04-04·CVSS 7.3
CVE-2024-31083 [HIGH] X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server, xwayland.
It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)
It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
xorg-x11-server: Heap buffer overread/data leakage in ProcAppleDRICreatePixmap
vendor_redhat·2024-04-03·CVSS 7.3
CVE-2024-31082 [HIGH] CWE-126 xorg-x11-server: Heap buffer overread/data leakage in ProcAppleDRICreatePixmap
xorg-x11-server: Heap buffer overread/data leakage in ProcAppleDRICreatePixmap
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds r
Debian
CVE-2024-31082: xorg-server - A heap-based buffer over-read vulnerability was found in the X.org server's Proc...
vendor_debian·2024·CVSS 7.3
CVE-2024-31082 [HIGH] CVE-2024-31082: xorg-server - A heap-based buffer over-read vulnerability was found in the X.org server's Proc...
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u7)
bullseye: re
OSV
xorg-server, xwayland regression
osv·2024-04-09·CVSS 7.3
CVE-2024-31080 [HIGH] xorg-server, xwayland regression
xorg-server, xwayland regression
USN-6721-1 fixed vulnerabilities in X.Org X Server. That fix was incomplete
resulting in a regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)
It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)
OSV
CVE-2024-31082: A heap-based buffer over-read vulnerability was found in the X
osv·2024-04-04·CVSS 7.3
CVE-2024-31082 [HIGH] CVE-2024-31082: A heap-based buffer over-read vulnerability was found in the X
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
GHSA
GHSA-cm2m-f7gc-hv64: A heap-based buffer over-read vulnerability was found in the X
ghsa_unreviewed·2024-04-04
CVE-2024-31082 [HIGH] CWE-126 GHSA-cm2m-f7gc-hv64: A heap-based buffer over-read vulnerability was found in the X
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
OSV
xorg-server, xwayland vulnerabilities
osv·2024-04-04·CVSS 7.3
CVE-2024-31080 [HIGH] xorg-server, xwayland vulnerabilities
xorg-server, xwayland vulnerabilities
It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)
It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2024-31082https://bugzilla.redhat.com/show_bug.cgi?id=2271999https://lists.x.org/archives/xorg-announce/2024-April/003497.htmlhttp://www.openwall.com/lists/oss-security/2024/04/03/13http://www.openwall.com/lists/oss-security/2024/04/12/10https://access.redhat.com/security/cve/CVE-2024-31082https://bugzilla.redhat.com/show_bug.cgi?id=2271999https://lists.x.org/archives/xorg-announce/2024-April/003497.html
2024-04-04
Published