Uploaded image for project: 'Funtoo Linux'
  1. Funtoo Linux
  2. FL-10207

x11-base/xorg-server - multiple input validation failures in X server extensions

    • Icon: Security Vulnerability Security Vulnerability
    • Resolution: Fixed
    • Icon: Important (Ebuild) Important (Ebuild)
    • None
    • None
    • This is a CVE and should be fixed.

      details

      from https://lists.x.org/archives/xorg/2022-July/061035.html

      Multiple input validation failures in X server extensions
      =========================================================

      All theses issues can lead to local privileges elevation on systems
      where the X server is running privileged and remote code execution for
      ssh X forwarding sessions.

      • CVE-2022-2319/ZDI-CAN-16062: X.Org Server ProcXkbSetGeometry Out-Of-Bounds
        Access

      The handler for the ProcXkbSetGeometry request of the Xkb extension does
      not properly validate the request length leading to out of bounds memory
      write.

      • CVE-2022-2320/ZDI-CAN-16070: X.Org Server ProcXkbSetDeviceInfo Out-Of-Bounds
        Access

      The handler for the ProcXkbSetDeviceInfo request of the Xkb extension
      does not properly validate the request length leading to out of bounds
      memory write.

      patches for backporting

      upstream fix

      in xorg-server 21.1.4

            mrl5 mrl5
            mrl5 mrl5
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: