XOrg Server and Xwayland Patched Against Multiple Security Vulnerabilities
A new X.Org Security Advisory was published today to warn users about CVE-2023-6816, a heap buffer overflow issue introduced in xorg-server v1.13.0 (released 2012), CVE-2024-0229, an out-of-bounds memory access issue introduced in xorg-server v1.1.1 (released 2006), and CVE-2024-21885, a heap buffer overflow issue introduced in xorg-server v1.10.0 (released 2011).
In addition, the new security advisory warns users about CVE-2024-21886, another heap buffer overflow issue introduced in xorg-server v1.13.0 (released 2012), CVE-2024-0409, a SELinux context corruption introduced in xorg-server v1.16.0 (released 2014), and CVE-2024-0408, a SELinux unlabeled GLX PBuffer issue introduced in xorg-server v1.10.0 (released 2011).