{"id":"CVE-2021-4008","details":"A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.","modified":"2026-03-15T22:41:44.889935Z","published":"2021-12-17T17:15:13.357Z","related":["ALSA-2022:1917","MGASA-2021-0573","SUSE-SU-2021:14863-1","SUSE-SU-2021:4064-1","SUSE-SU-2021:4065-1","SUSE-SU-2021:4066-1","SUSE-SU-2021:4069-1","SUSE-SU-2021:4070-1","SUSE-SU-2021:4071-1","openSUSE-SU-2021:1587-1","openSUSE-SU-2021:4070-1","openSUSE-SU-2024:11685-1","openSUSE-SU-2024:11699-1"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXTRPFEQLFZ6NT2LPLZEID664RGC3OCC/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDHYZM6FII35JA7J275MFCJO6ADJUPQX/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57DCF726O5LLTST4NBL5PQ7DLPB46HT/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NKLSZCY47QK4RCJFXITYFALCGPJAFXOK/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202305-30"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220114-0004/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00035.html"},{"type":"ADVISORY","url":"https://lists.x.org/archives/xorg-announce/2021-December/003122.html"},{"type":"ADVISORY","url":"https://lists.x.org/archives/xorg-announce/2021-December/003124.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-5027"},{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-21-1547/"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-4008.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"1.20.14"}]},{"events":[{"introduced":"0"},{"last_affected":"21.1.0"}]},{"events":[{"introduced":"0"},{"last_affected":"21.1.1"}]},{"events":[{"introduced":"0"},{"last_affected":"34"}]},{"events":[{"introduced":"0"},{"last_affected":"35"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"10.0"}]},{"events":[{"introduced":"0"},{"last_affected":"11.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}