CVE-2024-0408
MEDIUMDescription
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object that was never labeled and crash because the SID is NULL.
Is your site exposed to CVE-2024-0408?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| tigervnc | tigervnc |
| x.org | x_server |
| x.org | xwayland |
| fedoraproject | fedora |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
| redhat | enterprise_linux_desktop |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_power_big_endian |
| redhat | enterprise_linux_for_power_little_endian |
| redhat | enterprise_linux_for_scientific_computing |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_workstation |
References
Other References
Frequently Asked Questions
What is CVE-2024-0408? +
How severe is CVE-2024-0408? +
What products are affected by CVE-2024-0408? +
How do I check if I'm vulnerable to CVE-2024-0408? +
Related Vulnerabilities
A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By …
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary …
The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up …
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support …
Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, …
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when …