CVE-2024-31083
published 2024-04-05CVE-2024-31083: A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new…
PriorityP351high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.84%
76.7th percentile
A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:21.1.7-3+deb12u7 (bookworm) | xorg-server 2:21.1.7-3+deb12u7 (bookworm) |
| debian | xwayland | < xorg-server 2:21.1.7-3+deb12u7 (bookworm) | xorg-server 2:21.1.7-3+deb12u7 (bookworm) |
| msrc | cbl2_xorg-x11-server_1.20.10-11_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_xorg-x11-server_1.20.10-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| x.org | xorg-server | >= 0 < 2:1.20.11-1+deb11u13 | 2:1.20.11-1+deb11u13 |
| x.org | xorg-server | >= 0 < 2:21.1.7-3+deb12u7 | 2:21.1.7-3+deb12u7 |
| x.org | xorg-server | >= 0 < 2:21.1.11-3 | 2:21.1.11-3 |
| x.org | xorg-server | >= 0 < 2:21.1.11-3 | 2:21.1.11-3 |
| x.org | xorg-server | >= 0 < 2:1.20.13-1ubuntu1~20.04.17 | 2:1.20.13-1ubuntu1~20.04.17 |
| x.org | xorg-server | >= 0 < 2:1.20.13-1ubuntu1~20.04.16 | 2:1.20.13-1ubuntu1~20.04.16 |
| x.org | xorg-server | >= 0 < 2:21.1.4-2ubuntu1.7~22.04.10 | 2:21.1.4-2ubuntu1.7~22.04.10 |
| x.org | xorg-server | >= 0 < 2:21.1.4-2ubuntu1.7~22.04.9 | 2:21.1.4-2ubuntu1.7~22.04.9 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.11+esm12 | 2:1.15.1-0ubuntu2.11+esm12 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.11+esm11 | 2:1.15.1-0ubuntu2.11+esm11 |
| x.org | xorg-server | >= 0 < 2:1.18.4-0ubuntu0.12+esm13 | 2:1.18.4-0ubuntu0.12+esm13 |
| x.org | xorg-server | >= 0 < 2:1.18.4-0ubuntu0.12+esm12 | 2:1.18.4-0ubuntu0.12+esm12 |
| x.org | xorg-server | >= 0 < 2:1.19.6-1ubuntu4.15+esm8 | 2:1.19.6-1ubuntu4.15+esm8 |
| x.org | xorg-server | >= 0 < 2:1.19.6-1ubuntu4.15+esm7 | 2:1.19.6-1ubuntu4.15+esm7 |
| x.org | xwayland | >= 0 < 2:23.2.6-1 | 2:23.2.6-1 |
| x.org | xwayland | >= 0 < 2:23.2.6-1 | 2:23.2.6-1 |
| x.org | xwayland | >= 0 < 2:22.1.1-1ubuntu0.13 | 2:22.1.1-1ubuntu0.13 |
| x.org | xwayland | >= 0 < 2:22.1.1-1ubuntu0.12 | 2:22.1.1-1ubuntu0.12 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server regression
vendor_ubuntu·2024-04-09·CVSS 7.3
CVE-2024-31080 [HIGH] X.Org X Server regression
Title: X.Org X Server regression
Summary: A regression was fixed in X.Org X Server.
USN-6721-1 fixed vulnerabilities in X.Org X Server. That fix was incomplete
resulting in a regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)
It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)
Instructions: After a standard system update you need to restart -APP- to make
all the necessary changes.
Microsoft
Xorg-x11-server: use-after-free in procrenderaddglyphs
vendor_msrc·2024-04-09·CVSS 7.8
CVE-2024-31083 [HIGH] CWE-416 Xorg-x11-server: use-after-free in procrenderaddglyphs
Xorg-x11-server: use-after-free in procrenderaddglyphs
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lear
BSD
OpenBSD 7.4 Errata 016: SECURITY FIX
bsd_advisories·2024-04-08·CVSS 7.3
CVE-2024-31080 [HIGH] OpenBSD 7.4 Errata 016: SECURITY FIX
OpenBSD 7.4 Errata 016: SECURITY FIX
016: SECURITY FIX: April 8, 2024
All architectures Fix multiple heap buffer overread and data leakage in the X11 server Xi extension and use after free in the Render extension. CVE-2024-31080 CVE-2024-31081 CVE-2024-31083
BSD
OpenBSD 7.5 Errata 001: SECURITY FIX
bsd_advisories·2024-04-08·CVSS 7.3
CVE-2024-31080 [HIGH] OpenBSD 7.5 Errata 001: SECURITY FIX
OpenBSD 7.5 Errata 001: SECURITY FIX
001: SECURITY FIX: April 8, 2024
All architectures Fix multiple heap buffer overread and data leakage in the X11 server Xi extension and use after free in the Render extension. CVE-2024-31080 CVE-2024-31081 CVE-2024-31083
BSD
OpenBSD 7.3 Errata 028: SECURITY FIX
bsd_advisories·2024-04-08·CVSS 7.3
CVE-2024-31080 [HIGH] OpenBSD 7.3 Errata 028: SECURITY FIX
OpenBSD 7.3 Errata 028: SECURITY FIX
028: SECURITY FIX: April 8, 2024
All architectures Fix multiple heap buffer overread and data leakage in the X11 server Xi extension and use after free in the Render extension. CVE-2024-31080 CVE-2024-31081 CVE-2024-31083
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2024-04-04·CVSS 7.3
CVE-2024-31083 [HIGH] X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server, xwayland.
It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)
It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
xorg-x11-server: Use-after-free in ProcRenderAddGlyphs
vendor_redhat·2024-04-03·CVSS 7.8
CVE-2024-31083 [HIGH] CWE-416 xorg-x11-server: Use-after-free in ProcRenderAddGlyphs
xorg-x11-server: Use-after-free in ProcRenderAddGlyphs
A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.
A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to t
Debian
CVE-2024-31083: xorg-server - A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function o...
vendor_debian·2024·CVSS 7.8
CVE-2024-31083 [HIGH] CVE-2024-31083: xorg-server - A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function o...
A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u7)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u13)
forky: resolved (fixed in 2:21.1.11-3)
sid: resolved (fixed in 2:21.1.11-3)
trixie: resolved (fixed in 2:21.1.11-3)
OSV
xorg-server, xwayland regression
osv·2024-04-09·CVSS 7.3
CVE-2024-31080 [HIGH] xorg-server, xwayland regression
xorg-server, xwayland regression
USN-6721-1 fixed vulnerabilities in X.Org X Server. That fix was incomplete
resulting in a regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)
It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)
OSV
CVE-2024-31083: A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers
osv·2024-04-05·CVSS 7.8
CVE-2024-31083 [HIGH] CVE-2024-31083: A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers
A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.
GHSA
GHSA-q6w6-rjjj-5p52: A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers
ghsa_unreviewed·2024-04-05
CVE-2024-31083 [HIGH] CWE-416 GHSA-q6w6-rjjj-5p52: A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers
A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.
OSV
xorg-server, xwayland vulnerabilities
osv·2024-04-04·CVSS 7.3
CVE-2024-31080 [HIGH] xorg-server, xwayland vulnerabilities
xorg-server, xwayland vulnerabilities
It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)
It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:1785https://access.redhat.com/errata/RHSA-2024:2036https://access.redhat.com/errata/RHSA-2024:2037https://access.redhat.com/errata/RHSA-2024:2038https://access.redhat.com/errata/RHSA-2024:2039https://access.redhat.com/errata/RHSA-2024:2040https://access.redhat.com/errata/RHSA-2024:2041https://access.redhat.com/errata/RHSA-2024:2042https://access.redhat.com/errata/RHSA-2024:2080https://access.redhat.com/errata/RHSA-2024:2616https://access.redhat.com/errata/RHSA-2024:3258https://access.redhat.com/errata/RHSA-2024:3261https://access.redhat.com/errata/RHSA-2024:3343https://access.redhat.com/errata/RHSA-2024:9093https://access.redhat.com/errata/RHSA-2024:9122https://access.redhat.com/errata/RHSA-2025:12751https://access.redhat.com/security/cve/CVE-2024-31083https://bugzilla.redhat.com/show_bug.cgi?id=2272000http://www.openwall.com/lists/oss-security/2024/04/03/13http://www.openwall.com/lists/oss-security/2024/04/12/10https://access.redhat.com/errata/RHSA-2024:1785https://access.redhat.com/errata/RHSA-2024:2036https://access.redhat.com/errata/RHSA-2024:2037https://access.redhat.com/errata/RHSA-2024:2038https://access.redhat.com/errata/RHSA-2024:2039https://access.redhat.com/errata/RHSA-2024:2040https://access.redhat.com/errata/RHSA-2024:2041https://access.redhat.com/errata/RHSA-2024:2042https://access.redhat.com/errata/RHSA-2024:2080https://access.redhat.com/errata/RHSA-2024:2616https://access.redhat.com/errata/RHSA-2024:3258https://access.redhat.com/errata/RHSA-2024:3261https://access.redhat.com/errata/RHSA-2024:3343https://access.redhat.com/security/cve/CVE-2024-31083https://bugzilla.redhat.com/show_bug.cgi?id=2272000https://lists.debian.org/debian-lts-announce/2024/04/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/6TF7FZXOKHIKPZXYIMSQXKVH7WITKV3V/https://lists.fedoraproject.org/archives/list/[email protected]/message/EBLQJIAXEDMEGRGZMSH7CWUJHSVKUWLV/https://lists.fedoraproject.org/archives/list/[email protected]/message/P73U4DAAWLFZAPD75GLXTGMSTTQWW5AP/
2024-04-05
Published