Fedora Account System
Red Hat Associate
Red Hat Customer
input_constrain_cursor() writes barrier events into a fixed-size buffer without checking bounds. When more than 100 pointer barriers are active, the writes overflow the fixed buffer on the stack or heap. An authenticated X client can trigger this by creating more than 100 pointer barriers (using the XFIXES extension) and then generating pointer motion events (e.g. via XTEST). Both extensions are enabled by default. The buffer overflow can lead to arbitrary code execution or denial of service. Fixed in: xorg-server-21.1.25 and xwayland-24.1.14