CVE-2024-0408: Fedoraproject Fedora
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object that was never labeled and crash because the SID is NULL.
Affected products
- Fedoraproject Fedora: version 39 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux For IBM Z Systems: version 7.0 only
- Red Hat Enterprise Linux For Power Big Endian: version 7.0 only
- Red Hat Enterprise Linux For Power Little Endian: version 7.0 only
- Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Tigervnc Tigervnc: before 1.13.1 (fixed in 1.13.1)
- X.org X Server: before 21.1.11 (fixed in 21.1.11)
- X.org Xwayland: before 23.2.4 (fixed in 23.2.4)
Published 2024-01-18. Last modified 2026-06-17.