X.Org X Server, XWayland: Multiple Vulnerabilities — GLSA 202401-30

Multiple vulnerabilities have been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation or remote code execution.

Affected packages

x11-base/xorg-server on all architectures
Affected versions < 21.1.11
Unaffected versions >= 21.1.11
x11-base/xwayland on all architectures
Affected versions < 23.2.4
Unaffected versions >= 23.2.4

Background

The X Window System is a graphical windowing system based on a client/server model.

Description

Multiple vulnerabilities have been discovered in X.Org X Server and XWayland. Please review the CVE identifiers referenced below for details.

Impact

The X server can be crashed by a malicious client, or potentially be compromised for remote code execution in environments with X11 forwarding.

Workaround

Users can ensure no untrusted clients can access the running X implementation.

Resolution

All X.Org X Server users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=x11-base/xorg-server-21.1.11"
 

All XWayland users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=x11-base/xwayland-23.2.4"
 

References

Release date
January 31, 2024

Latest revision
January 31, 2024: 1

Severity
normal

Exploitable
remote

Bugzilla entries