Описание
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
Отчет
Xorg server does not run with root privileges in Red Hat Enterprise Linux 8, therefore this flaw has been rated as having Moderate impact.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | ||
Red Hat Enterprise Linux 7 | xorg-x11-server | Fixed | RHSA-2022:5905 | 04.08.2022 |
Red Hat Enterprise Linux 8 | xorg-x11-server | Fixed | RHSA-2022:7583 | 08.11.2022 |
Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Fixed | RHSA-2022:7583 | 08.11.2022 |
Red Hat Enterprise Linux 9 | xorg-x11-server | Fixed | RHSA-2022:8221 | 15.11.2022 |
Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland | Fixed | RHSA-2022:8222 | 15.11.2022 |
Показывать по
Дополнительная информация
Статус:
7.8 High
CVSS3
Связанные уязвимости
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
A flaw was found in the Xorg-x11-server. The specific flaw exists with ...
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
Уязвимость обработчика вызовов ProcXkbSetDeviceInfo сервера X.Org Server, позволяющая нарушителю выполнить произвольный код или повысить свои привилегии
7.8 High
CVSS3