You can sign up to get a daily email of our articles, see the Mailing List page.
We do often include affiliate links to earn us some pennies. See more here.

X.Org and Xwayland get new releases due to security issues

By - | Views: 32,103

Here's another reminder that checking regularly for updates is always a good thing, because there's new releases available for both the X.Org X and Xwayland due to multiple reported security issues.

First up, here's the actual listed issues reported and fixed:

  • CVE-2023-6816 can be triggered by passing an invalid array index to DeviceFocusEvent or ProcXIQueryPointer.
  • CVE-2024-0229 can be triggered if a device has both a button and a key class and zero buttons.
  • CVE-2024-21885 can be triggered if a device with a given ID was removed and a new device with the same ID added both in the same operation.
  • CVE-2024-21886 can be triggered by disabling a master device with disabled slave devices.
  • CVE-2024-0409 can be triggered by enabling SELinux xserver_object_manager and running a client.
  • CVE-2024-0408 can be triggered by enabling SELinux xserver_object_manager and creating a GLX PBuffer.

This security advisory went public on the X.Org mailing list this morning.

The issues are present in X.Org X server prior to 21.1.11 and Xwayland prior to 23.2.4, both of which were just announced and released. The xorg-server 21.1.11 release additionally "also contains a fix for XRandR to allow for multiple virtual monitors on a physical display" plus xwayland 23.2.4 additionally "also contains several other fixes for glamor, libEI support, and FreeBSD".

Article taken from GamingOnLinux.com.
15 Likes
About the author -
author picture
I am the owner of GamingOnLinux. After discovering Linux back in the days of Mandrake in 2003, I constantly came back to check on the progress of Linux until Ubuntu appeared on the scene and it helped me to really love it. You can reach me easily by emailing GamingOnLinux directly. Find me on Mastodon.
See more from me
26 comments
Page: 1/3»
  Go to:

slaapliedje Jan 16
This should be posted on X and break everyone's brain. :P
Quoting: slaapliedjeThis should be posted on X and break everyone's brain. :P

It took me a minute to realize how posting anything to a window system made any sense.
beko Jan 16
Quoting: eridanired123
Quoting: slaapliedjeThis should be posted on X and break everyone's brain. :P

It took me a minute to realize how posting anything to a window system made any sense.
Same. In fact it only clicked after reading your comment. What a mess
slaapliedje Jan 16
Quoting: eridanired123
Quoting: slaapliedjeThis should be posted on X and break everyone's brain. :P

It took me a minute to realize how posting anything to a window system made any sense.
Haha, indeed. I'm betting Elon would have taken over X.org if he could.
Quoting: beko
Quoting: eridanired123
Quoting: slaapliedjeThis should be posted on X and break everyone's brain. :P

It took me a minute to realize how posting anything to a window system made any sense.
Same. In fact it only clicked after reading your comment. What a mess
Ohhh, now I get it! He meant "the social media platform formerly known as Twitter"!
Pengling Jan 16
View PC info
  • Supporter
X posting about X on X, which people are viewing with X? ARGH!
chr Jan 17
Quoting: PenglingX posting about X on X, which people are viewing with X? ARGH!

This frustration is making me click the x button on the top-right of this window...
Quoting: chr
Quoting: PenglingX posting about X on X, which people are viewing with X? ARGH!

This frustration is making me click the x button on the top-right of this window...
Its making me press the X button on my Xbox controller while on my Xbox viewing this in Xplorer....... Shit is insane......
Quoting: slaapliedjeHaha, indeed. I'm betting Elon would have taken over X.org if he could.
Elon would be a Wayland hater if he's a Linux user lol
beko Jan 17
Tell me. I'm an X [X4 currently] gamer. That's ruining my childhood memories of the X-Verse.

…or on any 4X game, of course.
While you're here, please consider supporting GamingOnLinux on:

Reward Tiers: Patreon. Plain Donations: PayPal.

This ensures all of our main content remains totally free for everyone! Patreon supporters can also remove all adverts and sponsors! Supporting us helps bring good, fresh content. Without your continued support, we simply could not continue!

You can find even more ways to support us on this dedicated page any time. If you already are, thank you!
Login / Register


Or login with...
Sign in with Steam Sign in with Google
Social logins require cookies to stay logged in.