CVE-2024-31080
TigerVNC vulnerability analysis and mitigation

Overview

A heap-based buffer over-read vulnerability (CVE-2024-31080) was discovered in the X.org server's ProcXIGetSelectedEvents() function, first introduced in xorg-server-1.7.0 (2009). The vulnerability occurs when byte-swapped length values are used in replies, particularly when triggered by a client with a different endianness than the X server (X.Org Advisory, NVD).

Technical details

The vulnerability exists in the ProcXIGetSelectedEvents() function where it uses the byte-swapped length of the return data for the amount of data to return to the client when the client has a different endianness than the X server. This can cause the X server to read heap memory values and transmit them back to the client until encountering an unmapped page. While the attacker cannot control which specific memory is copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads (X.Org Advisory).

Impact

This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and transmit them back to the client until encountering an unmapped page, resulting in memory leakage and potential server crashes. The severity is rated as Important by Red Hat with a CVSS v3.1 base score of 7.3 HIGH (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H) (Red Hat Advisory).

Exploitability

The vulnerability requires a client with different endianness than the X server to trigger the issue. While the attacker cannot control the specific memory copied into the replies, they can potentially access sensitive information from the server's heap memory (X.Org Advisory).

Mitigation and workarounds

The vulnerability has been fixed in xorg-server-21.1.12 and xwayland-23.2.5. For Xwayland versions 23.1 and later, byte-swapping support is disabled by default, providing protection unless explicitly enabled with the +byteswappedclients option. The -byteswappedclients command-line option can be used to disable byte-swapping support. For the Xorg server, byte-swapping can be disabled by adding 'Option "AllowByteSwappedClients" "False"' to the ServerFlags section in /etc/X11/xorg.conf.d/ (X.Org Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

xwayland

Affected

bullseye

xorg-server: 2:1.20.11-1+deb11u13

Fixed

sid

xwayland: 2:23.2.6-1

Fixed

trixie

xwayland: 2:23.2.6-1

Fixed

SourceThis report was generated using AI

Related TigerVNC vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-50264HIGH7.8
  • NixOS logoNixOS
  • xorg-x11-server-devel
NoYesJun 05, 2026
CVE-2026-50261HIGH7.8
  • NixOS logoNixOS
  • xorg-x11-server-Xnest
NoYesJun 05, 2026
CVE-2026-50260HIGH7.8
  • NixOS logoNixOS
  • tigervnc-icons
NoYesJun 05, 2026
CVE-2026-50263MEDIUM5.5
  • NixOS logoNixOS
  • tigervnc-server-minimal
NoYesJun 05, 2026
CVE-2026-50262MEDIUM5.5
  • NixOS logoNixOS
  • xorg-x11-server-doc
NoYesJun 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management