Lack of data validation - Path Traversal In xwayland
Description
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | - | ||
debian 11 | 2:1.20.11-1+deb11u11 | ||
debian 12 | 2:21.1.7-3+deb12u5 | ||
debian 13 | 2:21.1.11-1 | ||
debian 14 | 2:21.1.11-1 | ||
debian 13 | 2:23.2.4-1 | ||
debian 14 | 2:23.2.4-1 | ||
rpm rhel9 | 0:22.1.9-5.el9 | ||
rpm rhel6 | - | - | |
rpm rhel6 | - | - |
1-10 of 14
10
Aliases
1. 2. 3. 4. 5.