Integer underflow in X.org Server - CVE-2021-3472

 

Integer underflow in X.org Server - CVE-2021-3472

Published: April 13, 2021


Vulnerability identifier: #VU52197
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2021-3472
CWE-ID: CWE-191
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to integer underflow within the XChangeFeedbackControl() function. A local user can run a specially crafted program to trigger integer underflow and escalate privileges on the system.


Affected software

X.org Server
Gentoo Linux
Amazon Linux AMI
SUSE Manager Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Workstation Extension
openEuler
Fedora
xorg-server (Debian package)
xorg-x11-server (Red Hat package)
xserver-xorg-core (Ubuntu package)
xserver-xorg-core-hwe-16.04 (Ubuntu package)
xorg-x11-server-extra
xorg-x11-server-extra-debuginfo
xorg-x11-server-debugsource
xorg-x11-server-debuginfo
xorg-x11-server
xorg-x11-server-sdk
xorg-x11-server-wayland
xorg-x11-server-wayland-debuginfo
xserver-xorg-core-hwe-18.04 (Ubuntu package)
xorg-x11-server-help
xorg-x11-server-Xephyr
xorg-x11-server-devel
xorg-x11-Xvnc
xorg-x11-server-Xwayland

How to mitigate CVE-2021-3472

Install updates from vendor's website.

X.org Server - update to 1.20.11
xorg-server (Debian package) - update to 2:1.20.4-1+deb10u3
xorg-x11-server (Red Hat package) - update to 1.20.4-16.el7_9
xserver-xorg-core (Ubuntu package) - addressed in versions 2:1.15.10ubuntu2.11+esm4, 2:1.18.4-0ubuntu0.12, 2:1.19.6-1ubuntu4.9, 2:1.20.9-2ubuntu1.2~20.04.2, 2:1.20.9-2ubuntu1.3
xserver-xorg-core-hwe-16.04 (Ubuntu package) - update to 2:1.19.6-1ubuntu4.1~16.04.6
xorg-x11-server-extra - addressed in versions 1.19.6-4.22.1, 1.19.6-8.30.1, 1.19.6-10.23.1, 1.20.3-14.5.16.1, 1.20.3-22.5.25.1, 7.4-27.122.40.1, 7.6_1.18.3-76.40.1
xorg-x11-server-extra-debuginfo - addressed in versions 1.19.6-4.22.1, 1.19.6-8.30.1, 1.19.6-10.23.1, 1.20.3-14.5.16.1, 1.20.3-22.5.25.1, 7.6_1.18.3-76.40.1
xorg-x11-server-debugsource - addressed in versions 1.19.6-4.22.1, 1.19.6-8.30.1, 1.19.6-10.23.1, 1.20.3-14.5.16.1, 1.20.3-22.5.25.1, 7.4-27.122.40.1, 7.6_1.18.3-76.40.1
xorg-x11-server-debuginfo - addressed in versions 1.19.6-4.22.1, 1.19.6-8.30.1, 1.19.6-10.23.1, 1.20.3-14.5.16.1, 1.20.3-22.5.25.1, 7.4-27.122.40.1, 7.6_1.18.3-76.40.1
xorg-x11-server - addressed in versions 1.19.6-4.22.1, 1.19.6-8.30.1, 1.19.6-10.23.1, 1.20.3-14.5.16.1, 1.20.3-22.5.25.1, 7.4-27.122.40.1, 7.6_1.18.3-76.40.1
xorg-x11-server-sdk - addressed in versions 1.19.6-8.30.1, 1.19.6-10.23.1, 1.20.3-14.5.16.1, 1.20.3-22.5.25.1
xorg-x11-server-wayland - update to 1.20.3-22.5.25.1
xorg-x11-server-wayland-debuginfo - update to 1.20.3-22.5.25.1
xserver-xorg-core-hwe-18.04 (Ubuntu package) - update to 2:1.20.8-2ubuntu2.2~18.04.5
xorg-x11-server-help - update to 1.20.8-7
xorg-x11-server-debugsource - update to 1.20.8-7
xorg-x11-server-Xephyr - update to 1.20.8-7
xorg-x11-server-devel - update to 1.20.8-7
xorg-x11-server-debuginfo - update to 1.20.8-7
xorg-x11-server - update to 1.20.8-7
xorg-x11-server - addressed in versions 1.20.11-1.fc32, 1.20.11-1.fc33, 1.20.11-1.fc34
xorg-x11-Xvnc - update to 7.4-27.122.40.1
xorg-x11-server-Xwayland - update to 21.1.1-1.fc34

External References

Related Security Bulletins