The vendor explicitly identifies these products as affected by this CVE.
- SCALANCE XCH328 (6GK5328-4TS01-2EC2)
- SCALANCE XCM324 (6GK5324-8TS01-2AC2)
- SCALANCE XCM328 (6GK5328-4TS01-2AC2)
- SCALANCE XCM332 (6GK5332-0GA01-2AC2)
- SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3)
- SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3)
- SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3)
- SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3)
- SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3)
- SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3)
- SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3)
- Summary
- A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
- Remediation
- Update to V2.4 or later version
