CVE-2024-9632: Red Hat Enterprise Linux 10
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:24.1.5-3.el10_0 (fixed in 0:24.1.5-3.el10_0)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 6 Extended Lifecycle Support - Extension: before 0:1.1.0-25.el6_10.13 (fixed in 0:1.1.0-25.el6_10.13)
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:1.8.0-34.el7_9 (fixed in 0:1.8.0-34.el7_9)
- Red Hat Red Hat Enterprise Linux 8: before 0:1.20.11-25.el8_10 (fixed in 0:1.20.11-25.el8_10); before 0:21.1.3-17.el8_10 (fixed in 0:21.1.3-17.el8_10); before 0:1.13.1-14.el8_10 (fixed in 0:1.13.1-14.el8_10)
- Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 0:1.9.0-15.el8_2.12 (fixed in 0:1.9.0-15.el8_2.12)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:1.11.0-8.el8_4.11 (fixed in 0:1.11.0-8.el8_4.11)
- Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service: before 0:1.11.0-8.el8_4.11 (fixed in 0:1.11.0-8.el8_4.11)
- Red Hat Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions: before 0:1.11.0-8.el8_4.11 (fixed in 0:1.11.0-8.el8_4.11)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:1.12.0-6.el8_6.12 (fixed in 0:1.12.0-6.el8_6.12)
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:1.12.0-6.el8_6.12 (fixed in 0:1.12.0-6.el8_6.12)
- Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:1.12.0-6.el8_6.12 (fixed in 0:1.12.0-6.el8_6.12)
- Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 0:1.12.0-15.el8_8.11 (fixed in 0:1.12.0-15.el8_8.11)
- Red Hat Red Hat Enterprise Linux 9: before 0:1.14.1-1.el9_5 (fixed in 0:1.14.1-1.el9_5); before 0:1.20.11-28.el9_6 (fixed in 0:1.20.11-28.el9_6); before 0:23.2.7-3.el9_6 (fixed in 0:23.2.7-3.el9_6)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:1.11.0-22.el9_0.12 (fixed in 0:1.11.0-22.el9_0.12)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:1.12.0-14.el9_2.9 (fixed in 0:1.12.0-14.el9_2.9)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:1.13.1-8.el9_4.4 (fixed in 0:1.13.1-8.el9_4.4)
Published 2024-10-30. Last modified 2026-06-17.