{"id":"RHSA-2024:2995","summary":"Red Hat Security Advisory: xorg-x11-server security update","modified":"2026-03-25T10:05:18Z","published":"2024-09-16T15:35:55Z","upstream":["CVE-2023-5367","CVE-2023-5380","CVE-2023-6377","CVE-2023-6478","CVE-2023-6816","CVE-2024-0229","CVE-2024-0408","CVE-2024-0409","CVE-2024-21885","CVE-2024-21886"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2995"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#moderate"},{"type":"ARTICLE","url":"https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.10_release_notes/index"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2243091"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2244736"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2253291"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2253298"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2256540"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2256542"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2256690"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2257689"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2257690"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2995.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-5367"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-5367"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5367"},{"type":"ARTICLE","url":"https://lists.x.org/archives/xorg-announce/2023-October/003430.html"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-5380"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-5380"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5380"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-6377"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-6377"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6377"},{"type":"ARTICLE","url":"https://gitlab.freedesktop.org/xorg/xserver/-/commit/0c1a93d319558fe3ab2d94f51d174b4f93810afd"},{"type":"ARTICLE","url":"https://lists.x.org/archives/xorg-announce/2023-December/003435.html"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-6478"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-6478"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6478"},{"type":"ARTICLE","url":"https://gitlab.freedesktop.org/xorg/xserver/-/commit/14f480010a93ff962fef66a16412fafff81ad632"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-6816"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2257691"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-6816"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6816"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2024-0229"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2024-0229"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0229"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2024-0408"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2024-0408"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0408"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2024-0409"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2024-0409"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0409"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2024-21885"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2024-21885"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21885"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2024-21886"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2024-21886"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21886"}],"affected":[{"package":{"name":"xorg-x11-server","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xdmx","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xdmx"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xdmx-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xdmx-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xephyr","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xephyr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xephyr-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xephyr-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xnest","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xnest"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xnest-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xnest-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xorg","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xorg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xorg-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xorg-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xvfb","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xvfb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xvfb-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-Xvfb-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-common","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-debugsource","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-devel","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-source","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/xorg-x11-server-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xdmx","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xdmx"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xdmx-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xdmx-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xephyr","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xephyr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xephyr-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xephyr-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xnest","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xnest"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xnest-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xnest-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xorg","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xorg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xorg-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xorg-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xvfb","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xvfb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-Xvfb-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-Xvfb-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-common","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-debugsource","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-devel","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}},{"package":{"name":"xorg-x11-server-source","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/xorg-x11-server-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.20.11-22.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:2995.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}