CVE-2024-0409: Fedoraproject Fedora

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.

Affected products

  • Fedoraproject Fedora: version 39 only
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 7.0 only
  • Red Hat Enterprise Linux For Power Big Endian: version 7.0 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0 only
  • Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Tigervnc Tigervnc: before 1.13.1 (fixed in 1.13.1)
  • X.org X Server: before 21.1.11 (fixed in 21.1.11)
  • X.org Xwayland: before 23.2.4 (fixed in 23.2.4)

Published 2024-01-18. Last modified 2026-06-17.