Vulnerability CVE-2022-4283: Information
Description
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
xorg-server | sisyphus | 1.20.5-alt1 | 21.1.13-alt1 | ALT-PU-2019-1984-1 | 231384 | Fixed |
xorg-server | p10 | 1.20.5-alt1 | 1.20.14-alt13 | ALT-PU-2019-1984-1 | 231384 | Fixed |
xorg-server | p9 | 1.20.5-alt2 | 1.20.8-alt12 | ALT-PU-2019-2671-1 | 237324 | Fixed |
xorg-server | c10f1 | 1.20.5-alt1 | 1.20.14-alt12 | ALT-PU-2019-1984-1 | 231384 | Fixed |
xorg-server | c9f2 | 1.20.8-alt12 | 1.20.8-alt12 | ALT-PU-2024-3261-2 | 341756 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2151761 |
|
https://access.redhat.com/security/cve/CVE-2022-4283 |
|
DSA-5304 |
|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z67QC4C3I2FI2WRFIUPEHKC36J362MLA/ |
|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NELB7YDWRABYYBG4UPTHRBDTKJRV5M2/ |
|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXDF2O5PPLE3SVAJJYUOSAD5QZ4TWQ2G/ |
|
https://security.gentoo.org/glsa/202305-30 |