Bug 1944167 (CVE-2021-3472)

Summary: CVE-2021-3472 xorg-x11-server: XChangeFeedbackControl integer underflow leads to privilege escalation
Product: [Other] Security Response Reporter: msiddiqu
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: ajax, bskeggs, caillon+fedoraproject, jglisse, ofourdan, rhughes, rstrode, sandmann, security-response-team, xgl-maint
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: xorg-x11-server 1.20.11 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in xorg-x11-server. An interger underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-05-19 14:33:40 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1944956, 1944957, 1944958, 1949217    
Bug Blocks: 1944094, 1944169    

Description msiddiqu 2021-03-29 13:02:59 UTC
A vulnerability was found affecting X.Org-Server, where integer underflow exist in xserver, ProcXChangeFeedbackControl() leading to local privilege escalation

Comment 1 msiddiqu 2021-03-29 13:03:02 UTC
Acknowledgments:

Name: Trend MicJan-Niklas Sohnro Zero Day Initiative (Trend Micro Zero Day Initiative)

Comment 3 Huzaifa S. Sidhpurwala 2021-03-31 05:21:21 UTC
Statement:

Xorg server does not run with root  privileges in Red Hat Enterprise Linux 8, therefore this flaw has been rated as having moderate impact for Red Hat Enterprise linux 8.

Comment 4 Guilherme de Almeida Suckevicz 2021-04-13 17:50:37 UTC
Created xorg-x11-server tracking bugs for this issue:

Affects: fedora-all [bug 1949217]

Comment 6 Huzaifa S. Sidhpurwala 2021-04-14 03:40:10 UTC
External References:

https://lists.x.org/archives/xorg-announce/2021-April/003080.html

Comment 7 errata-xmlrpc 2021-05-19 10:53:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2021:2033 https://access.redhat.com/errata/RHSA-2021:2033

Comment 8 Product Security DevOps Team 2021-05-19 14:33:40 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-3472