CVE-2024-9632

Updated: 2025-11-28 14:33:22.021641

Description:

A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU xorg-x11-server-Xwayland 21.1.3 7.8 HIGH Released CLSA-2025:1764081820 2025-11-25 21:21:51
AlmaLinux 9.2 ESU tigervnc 1.12.0 7.8 HIGH Released CLSA-2025:1744223313 2025-04-10 03:12:20
CentOS 7 ELS xorg-x11-server 1.20.4 7.8 HIGH Released CLSA-2025:1765223770 2025-12-20 04:34:52
Oracle Linux 7 ELS xorg-x11-server 1.20.4 7.8 HIGH Released CLSA-2025:1765209058 2025-12-08 17:19:16
Oracle Linux 7 ELS tigervnc 1.8.0 7.8 HIGH Already Fixed 2025-10-07 16:39:33
RHEL 7 ELS xorg-x11-server 1.20.4 7.8 HIGH Released CLSA-2025:1765209523 2025-12-08 17:19:14