#VU59048 Out-of-bounds write in X.org Server - CVE-2021-4011
Published: December 17, 2021 / Updated: December 21, 2021
X.org Server
X.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in the SwapCreateRegister() function in the Record extension. A local user can send a specially crafted RecordCreateContext and RecordRegisterClients requests, trigger an out-of-bounds write and execute arbitrary code with elevated privileges.