
Cloud Vulnerability DB
A community-led vulnerabilities database
A heap-based buffer over-read vulnerability (CVE-2024-31080) was discovered in the X.org server's ProcXIGetSelectedEvents() function, first introduced in xorg-server-1.7.0 (2009). The vulnerability occurs when byte-swapped length values are used in replies, particularly when triggered by a client with a different endianness than the X server (X.Org Advisory, NVD).
The vulnerability exists in the ProcXIGetSelectedEvents() function where it uses the byte-swapped length of the return data for the amount of data to return to the client when the client has a different endianness than the X server. This can cause the X server to read heap memory values and transmit them back to the client until encountering an unmapped page. While the attacker cannot control which specific memory is copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads (X.Org Advisory).
This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and transmit them back to the client until encountering an unmapped page, resulting in memory leakage and potential server crashes. The severity is rated as Important by Red Hat with a CVSS v3.1 base score of 7.3 HIGH (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H) (Red Hat Advisory).
The vulnerability requires a client with different endianness than the X server to trigger the issue. While the attacker cannot control the specific memory copied into the replies, they can potentially access sensitive information from the server's heap memory (X.Org Advisory).
The vulnerability has been fixed in xorg-server-21.1.12 and xwayland-23.2.5. For Xwayland versions 23.1 and later, byte-swapping support is disabled by default, providing protection unless explicitly enabled with the +byteswappedclients option. The -byteswappedclients command-line option can be used to disable byte-swapping support. For the Xorg server, byte-swapping can be disabled by adding 'Option "AllowByteSwappedClients" "False"' to the ServerFlags section in /etc/X11/xorg.conf.d/ (X.Org Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."