#VU99493 Heap-based buffer overflow in X.org Server and Xwayland - CVE-2024-9632
Published: October 29, 2024 / Updated: November 6, 2024
X.org Server
Xwayland
X.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the XkbSetCompatMap() function in xkb/xkb.c. A local user can pass a specially crafted bitmap to the X.Org server, trigger a heap-based buffer overflow and execute arbitrary code with elevated privileges.