A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
                
            References
                    Configurations
                    No configuration.
History
                    04 Aug 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
21 Nov 2024, 09:12
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | |
| References | () https://access.redhat.com/errata/RHSA-2024:1785 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2036 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2037 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2038 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2039 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2040 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2041 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2042 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2080 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:2616 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:3258 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:3261 - | |
| References | () https://access.redhat.com/errata/RHSA-2024:3343 - | |
| References | () https://access.redhat.com/security/cve/CVE-2024-31080 - | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2271997 - | 
12 Nov 2024, 15:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
16 Sep 2024, 19:16
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
24 May 2024, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
22 May 2024, 17:16
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
01 May 2024, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
01 May 2024, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
30 Apr 2024, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
29 Apr 2024, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
25 Apr 2024, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
24 Apr 2024, 02:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
19 Apr 2024, 23:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
15 Apr 2024, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
11 Apr 2024, 23:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
04 Apr 2024, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-04-04 14:15
Updated : 2025-08-04 21:15
NVD link : CVE-2024-31080
Mitre link : CVE-2024-31080
CVE.ORG link : CVE-2024-31080
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-126
                        
            Buffer Over-read
