CVE-2024-31083 - CVE House
Back to Database
Status published High CVE-2024-31083

Xorg-x11-server: use-after-free in procrenderaddglyphs

Vulnerability Description

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-31083

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Extended Update Support, Red Hat Enterprise Linux 9.2 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6
Vulnerable Versions:
21.1.12, 0:1.1.0-25.el6_10.13, 0:1.20.4-29.el7_9, 0:1.8.0-33.el7_9, 0:1.13.1-2.el8_9.10, 0:1.20.11-23.el8_10, 0:1.13.1-10.el8_10, 0:21.1.3-16.el8_10, 0:1.9.0-15.el8_2.11, 0:1.11.0-8.el8_4.10, 0:1.12.0-6.el8_6.11, 0:1.12.0-15.el8_8.10, 0:1.13.1-8.el9_4.3, 0:23.2.7-1.el9, 0:1.20.11-26.el9, 0:1.11.0-22.el9_0.11, 0:1.12.0-14.el9_2.8

Timeline

Official Publish: April 5th, 2024
Last Modified: November 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)