Wind River Support Network

HomeDefectsLIN1021-271
Fixed

LIN1021-271 : Security Advisory - xserver-xorg - CVE-2021-3472

Created: May 24, 2021    Updated: Dec 17, 2021
Resolved Date: Jul 6, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.3
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Insufficient checks on the lengths of the XInput extension ChangeFeedbackControl request can lead to out of bounds memory accesses in the X server.

https://gitlab.freedesktop.org/xorg/xserver/-/commit/7aaf54a1884f71dc363f0b884e57bcb67407a6cd

CREATE(Triage):(User=admin) CVE-2021-3472 (https://nvd.nist.gov/vuln/detail/CVE-2021-3472)

CVEs


Live chat
Online