← back
CVE-2024-21886

Xorg-x11-server: heap buffer overflow in disabledevice

CVSS 7.8 HIGHEPSS 1.4%CWE-122
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.8EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
28 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in some circumstances, remote code execution in SSH X11 forwarding environments.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →