Description
A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 11 | | =2:1.20.11-1 || =2:1.20.11-1+deb11u1 || =2:1.20.11-1+deb11u10 || =2:1.20.11-1+deb11u11 || =2:1.20.11-1+deb11u12 || =2:1.20.11-1+deb11u13 || =2:1.20.11-1+deb11u14 || =2:1.20.11-1+deb11u15 || =2:1.20.11-1+deb11u16 || =2:1.20.11-1+deb11u17 || =2:1.20.11-1+deb11u2 || =2:1.20.11-1+deb11u3 || =2:1.20.11-1+deb11u4 || =2:1.20.11-1+deb11u5 || =2:1.20.11-1+deb11u6 || =2:1.20.11-1+deb11u7 || =2:1.20.11-1+deb11u8 || =2:1.20.11-1+deb11u9 || =2:1.20.13-1 || =2:1.20.13-2 || =2:1.20.13-3 || =2:1.20.14-1 || =2:21.1.1-1 || =2:21.1.1-2 || =2:21.1.10-1 || =2:21.1.11-1 || =2:21.1.11-2 || =2:21.1.11-3 || =2:21.1.12-1 || =2:21.1.13-1 || =2:21.1.13-2 || =2:21.1.13-3 || =2:21.1.13-3.1 || =2:21.1.14-1 || =2:21.1.14-2 || =2:21.1.15-1 || =2:21.1.15-2 || =2:21.1.15-3 || =2:21.1.16-1 || =2:21.1.16-1.1 || =2:21.1.16-1.2 || =2:21.1.16-1.3 || =2:21.1.18-1 || =2:21.1.18-2 || =2:21.1.20-1 || =2:21.1.21-1 || =2:21.1.22-1 || =2:21.1.3-1 || =2:21.1.3-2 || =2:21.1.4-1 || =2:21.1.4-2 || =2:21.1.4-3 || =2:21.1.5-1 || =2:21.1.6-1 || =2:21.1.7-1 || =2:21.1.7-2 || =2:21.1.7-3 || =2:21.1.8-1 || =2:21.1.9-1 || =2:21.1.9-1+hurd.1 | - |
 debian 12 | | =2:21.1.10-1 || =2:21.1.11-1 || =2:21.1.11-2 || =2:21.1.11-3 || =2:21.1.12-1 || =2:21.1.13-1 || =2:21.1.13-2 || =2:21.1.13-3 || =2:21.1.13-3.1 || =2:21.1.14-1 || =2:21.1.14-2 || =2:21.1.15-1 || =2:21.1.15-2 || =2:21.1.15-3 || =2:21.1.16-1 || =2:21.1.16-1.1 || =2:21.1.16-1.2 || =2:21.1.16-1.3 || =2:21.1.18-1 || =2:21.1.18-2 || =2:21.1.20-1 || =2:21.1.21-1 || =2:21.1.22-1 || =2:21.1.7-3 || =2:21.1.7-3+deb12u1 || =2:21.1.7-3+deb12u10 || =2:21.1.7-3+deb12u11 || =2:21.1.7-3+deb12u2 || =2:21.1.7-3+deb12u3 || =2:21.1.7-3+deb12u4 || =2:21.1.7-3+deb12u5 || =2:21.1.7-3+deb12u6 || =2:21.1.7-3+deb12u7 || =2:21.1.7-3+deb12u8 || =2:21.1.7-3+deb12u9 || =2:21.1.8-1 || =2:21.1.9-1 || =2:21.1.9-1+hurd.1 | - |
 debian 13 | | =2:21.1.16-1.3 || =2:21.1.16-1.3+deb13u1 || =2:21.1.18-1 || =2:21.1.18-2 || =2:21.1.20-1 || =2:21.1.21-1 || =2:21.1.22-1 | - |
 debian 14 | | =2:21.1.16-1.3 || =2:21.1.18-1 || =2:21.1.18-2 || =2:21.1.20-1 || =2:21.1.21-1 || =2:21.1.22-1 | - |
 rpm rhel9 | | | 0:1.13.1-8.el9 |
 rpm rhel6 | | - | - |
 rpm rhel7 | | - | - |
 rpm rhel8 | | - | - |
 rpm rhel9 | | - | - |