CVE-2024-21886

Updated: 2025-08-20 00:20:44.454664

Description:

A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in some circumstances, remote code execution in SSH X11 forwarding environments.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU xorg-x11-server-Xwayland 21.1.3 7.8 HIGH Released CLSA-2025:1764027165 2025-11-25 02:26:39
AlmaLinux 9.2 ESU tigervnc 1.12.0 7.8 HIGH Released CLSA-2025:1744632481 2025-04-15 05:41:47