A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xdmx" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xdmx-dbgsym" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xdmx-tools" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xdmx-tools-dbgsym" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xmir" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xmir-dbgsym" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xnest" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xnest-dbgsym" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xorg-server-source" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-common" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xephyr" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xephyr-dbgsym" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xorg-core" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xorg-core-dbgsym" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xorg-core-udeb" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xorg-dev" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xorg-legacy" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xorg-legacy-dbgsym" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xserver-xorg-xmir" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xvfb" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xvfb-dbgsym" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xwayland" }, { "binary_version": "2:1.19.6-1ubuntu4.15", "binary_name": "xwayland-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xorg-server-source-hwe-18.04" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xserver-xephyr-hwe-18.04" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xserver-xephyr-hwe-18.04-dbgsym" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xserver-xorg-core-hwe-18.04" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xserver-xorg-core-hwe-18.04-dbgsym" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xserver-xorg-dev-hwe-18.04" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xserver-xorg-legacy-hwe-18.04" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xserver-xorg-legacy-hwe-18.04-dbgsym" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xwayland-hwe-18.04" }, { "binary_version": "2:1.20.8-2ubuntu2.2~18.04.11", "binary_name": "xwayland-hwe-18.04-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-common" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-common-dbgsym" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-scraping-server" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-scraping-server-dbgsym" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-standalone-server" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-standalone-server-dbgsym" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-viewer" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-viewer-dbgsym" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-xorg-extension" }, { "binary_version": "1.10.1+dfsg-3ubuntu0.20.04.1", "binary_name": "tigervnc-xorg-extension-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xdmx" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xdmx-dbgsym" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xdmx-tools" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xdmx-tools-dbgsym" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xnest" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xnest-dbgsym" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xorg-server-source" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-common" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-xephyr" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-xephyr-dbgsym" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-xorg-core" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-xorg-core-dbgsym" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-xorg-core-udeb" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-xorg-dev" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-xorg-legacy" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xserver-xorg-legacy-dbgsym" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xvfb" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xvfb-dbgsym" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xwayland" }, { "binary_version": "2:1.20.13-1ubuntu1~20.04.8", "binary_name": "xwayland-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-common" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-common-dbgsym" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-scraping-server" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-scraping-server-dbgsym" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-standalone-server" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-standalone-server-dbgsym" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-tools" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-tools-dbgsym" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-viewer" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-viewer-dbgsym" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-xorg-extension" }, { "binary_version": "1.12.0+dfsg-4ubuntu0.22.04.1", "binary_name": "tigervnc-xorg-extension-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xnest" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xnest-dbgsym" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xorg-server-source" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xserver-common" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xserver-xephyr" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xserver-xephyr-dbgsym" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xserver-xorg-core" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xserver-xorg-core-dbgsym" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xserver-xorg-dev" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xserver-xorg-legacy" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xserver-xorg-legacy-dbgsym" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xvfb" }, { "binary_version": "2:21.1.3-2ubuntu2.9", "binary_name": "xvfb-dbgsym" } ] }