QID 355170

Date Published: 2023-05-29

QID 355170: Amazon Linux Security Advisory for xorg-x11-server : ALAS2023-2023-102

a flaw was found in the xorg-x11-server.
An out-of-bounds access issue can occur in the sprocrendercompositeglyphs function due to improper validation of the request length. (
( CVE-2021-4008) a flaw was found in xorg-x11-server.
An out-of-bounds access can occur in the sprocxfixescreatepointerbarrier function. (
( CVE-2021-4009) a flaw was found in xorg-x11-server where an out-of-bounds access can occur in the sprocscreensaversuspend function. (
( CVE-2021-4010) a flaw was found in xorg-x11-server where an out-of-bounds access can occur in the swapcreateregister function. (
( CVE-2021-4011) a vulnerability classified as critical was found in x.org server.
Affected by this vulnerability is the function _getcountedstring of the file xkb/xkb.c.
The manipulation leads to buffer overflow.
It is recommended to apply a patch to fix this issue.
The associated identifier of this vulnerability is vdb-211051. (
( CVE-2022-3550) a vulnerability, which was classified as problematic, has been found in x.org server.
Affected by this issue is the function procxkbgetkbdbyname of the file xkb/xkb.c.
The manipulation leads to memory leak.
The identifier of this vulnerability is vdb-211052. (
( CVE-2022-3551) a vulnerability was found in x.org.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2023-2023-102 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2023-2023-102 amazon linux 2023 URL Logo alas.aws.amazon.com/AL2023/ALAS-2023-102.html