VDB
BDU%3A2024-00675
BDU%3A2024-00675
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функции DisableDevice реализации протокола Wayland для X.Org XWayland, реализации сервера X Window System X.Org Server, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:1.11.0-8.el8_4.8 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:21.1.3-15.el8 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.13.1-3.el9_3.6 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:22.1.9-5.el9 |
| Red Hat | Red Hat Enterprise Linux 7 | 0:1.20.4-27.el7_9 |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | 0:1.12.0-15.el8_8.7 |
| Red Hat | Red Hat Enterprise Linux 7 | 0:1.8.0-31.el7_9 |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | 0:1.9.0-15.el8_2.9 |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:1.11.0-22.el9_0.8 |
| Red Hat | Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | 0:1.1.0-25.el6_10.13 |
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | 0:1.11.0-8.el8_4.8 |
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 0:1.11.0-8.el8_4.8 |
| xorg | xserver | * |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 0:1.9.0-15.el8_2.9 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.20.11-22.el8 |
| xorg | xwayland | * |
| Red Hat Inc., ООО «РусБИТех-Астра», Сообщество свободного программного обеспечения, Canonical Ltd., ООО «Ред Софт», АО «ИВК», АО «НТЦ ИТ РОСА», X.Org Foundation, АО "НППКТ" | Red Hat Enterprise Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), Debian GNU/Linux, Ubuntu, РЕД ОС (запись в едином реестре российских программ №3751), Альт 8 СП (запись в едином реестре российских программ №4305), РОСА Кобальт (запись в едином реестре российских программ №1999), РОСА ХРОМ (запись в едином реестре российских программ №1607), АЛЬТ СП 10, X.Org Server, XWayland, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913) | |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.20.11-24.el9 |
| 1.21.1.7 | ||
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:1.12.0-14.el9_2.5 |
…and 4 more
Timeline
- Jan 18, 2024 PoC Published
- Jan 25, 2024 CVE Published
- Feb 11, 2024 PoC Published
- Feb 28, 2024 PoC Published
- Feb 28, 2024 PoC Published
- Mar 5, 2025 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Jun 16, 2026 Distribution Patch
- Jun 16, 2026 Distribution Patch
- Jun 16, 2026 Distribution Patch
References
- https://ubuntu.com/security/notices/USN-6587-1 url
- https://abf.rosalinux.ru/advisories/ROSA-SA-2024-2352 url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2024-0830SE17 advisory
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2575 advisory
- https://access.redhat.com/security/cve/CVE-2024-21886 url
- https://security-tracker.debian.org/tracker/CVE-2024-21886 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.10/ url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20241017SE16 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2576 advisory
- RHSA-2024:0557 vendor-advisory
- RHSA-2024:0558 vendor-advisory
- RHSA-2024:0614 vendor-advisory
- RHSA-2024:0621 vendor-advisory
- RHSA-2024:0626 vendor-advisory
- RHSA-2024:0629 vendor-advisory
- RHSA-2024:2995 vendor-advisory
- RHSA-2025:12751 vendor-advisory
- RHSA-2024:0320 vendor-advisory
- RHSA-2024:0597 vendor-advisory
- RHSA-2024:0607 vendor-advisory
…and 16 more