Impact
The vulnerability is a heap buffer overflow that local attackers with an X connection can trigger by supplying PCX fonts to the X server or through the X SetFont operation, where glyph boundary checks are missing. As a result, an attacker can corrupt heap memory and potentially execute arbitrary code or crash the affected process. The weakness is classified as CWE‑122.
Affected Systems
The affected products are X.Org xorg‑server with versions prior to 21.2.24 and X.Org xwayland with versions before 24.1.13. Any deployment of these packages that has not applied the recent patch is vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The vulnerability is local; an adversary must have the ability to open an X connection and provide a crafted PCX font. Successful exploitation would allow the attacker to perform memory corruption on the execution or cause a denial of service. Because it is local, the attack surface is limited to users or processes that can interact with the X server.
OpenCVE Enrichment