VDB
BDU%3A2024-02764
BDU%3A2024-02764
PUBLISHED
CVSS 7.599999904632568 HIGH
Уязвимость пакета xorg-server, связанная с целочисленным переполнением или обходом, позволяющая нарушитель раскрыть конфиденциальную информацию
Risk Scores
CVSS 3.1
7.599999904632568
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:1.11.0-8.el8_4.5 |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | 0:1.9.0-15.el8_2.6 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.20.11-24.el9 |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 0:1.12.0-6.el8_6.6 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.20.11-22.el8 |
| ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», АО «НТЦ ИТ РОСА», АО "НППКТ", Сообщество свободного программного обеспечения, X.Org Foundation | РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), РОСА ХРОМ (запись в едином реестре российских программ №1607), АЛЬТ СП 10, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), XWayland, Xorg-server | |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.13.1-3.el9_3.3 |
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | 0:1.11.0-8.el8_4.5 |
| Red Hat | Red Hat Enterprise Linux 7 | 0:1.20.4-25.el7_9 |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:1.11.0-22.el9_0.5 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.13.1-2.el8_9.4 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:22.1.9-5.el9 |
| Red Hat | Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | 0:1.1.0-25.el6_10.13 |
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 0:1.11.0-8.el8_4.5 |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 0:1.9.0-15.el8_2.6 |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | 0:1.12.0-15.el8_8.4 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:21.1.3-15.el8 |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:1.12.0-14.el9_2.2 |
| Red Hat | Red Hat Enterprise Linux 7 | 0:1.8.0-28.el7_9 |
…and 1 more
Timeline
- Dec 13, 2023 CVE Published
- Jan 7, 2024 PoC Published
- Apr 12, 2024 PoC Published
- Mar 5, 2025 CVE Updated
- May 31, 2026 Distribution Patch
- May 31, 2026 Distribution Patch
- May 31, 2026 Distribution Patch
- May 31, 2026 Security Advisory
- May 31, 2026 Security Advisory
- May 31, 2026 Security Advisory
- May 31, 2026 Distribution Patch
- May 31, 2026 Distribution Patch
References
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2566 advisory
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2576 advisory
- https://redos.red-soft.ru/support/secure/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2024-0830SE17 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2575 url
- https://gitlab.freedesktop.org/xorg/xserver/-/commit/14f480010a93ff962fef66a16412fafff81ad632 advisory
- RHSA-2024:0014 vendor-advisory
- RHSA-2024:2170 vendor-advisory
- RHSA-2025:12751 vendor-advisory
- https://lists.x.org/archives/xorg-announce/2023-December/003435.html url
- http://www.openwall.com/lists/oss-security/2023/12/13/1 url
- RHSA-2023:7886 vendor-advisory
- RHSA-2024:0006 vendor-advisory
- RHSA-2024:0009 vendor-advisory
- RHSA-2024:0010 vendor-advisory
- RHSA-2024:0015 vendor-advisory
- RHSA-2024:0016 vendor-advisory
- RHSA-2024:0017 vendor-advisory
- RHSA-2024:0018 vendor-advisory
- RHSA-2024:0020 vendor-advisory
…and 16 more