CyberRota Analysis
AI-GeneratedLocal attackers with X connection access can exploit a heap buffer overflow vulnerability in the xorg-server and xwayland components, affecting versions prior to 21.2.24 and 24.1.13, respectively. This flaw arises from inadequate glyph boundary checks when handling PCX fonts, potentially allowing attackers to execute arbitrary code. Organizations using these X server implementations should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)