CVE-2022-2320
published 2022-09-01CVE-2022-2320: A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.57%
43.6th percentile
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:21.1.4-1 (bookworm) | xorg-server 2:21.1.4-1 (bookworm) |
| debian | xwayland | < xorg-server 2:21.1.4-1 (bookworm) | xorg-server 2:21.1.4-1 (bookworm) |
| x.org | x_server | — | — |
| x.org | xorg-server | >= 0 < 2:1.20.11-1+deb11u2 | 2:1.20.11-1+deb11u2 |
| x.org | xorg-server | >= 0 < 2:21.1.4-1 | 2:21.1.4-1 |
| x.org | xorg-server | >= 0 < 2:21.1.4-1 | 2:21.1.4-1 |
| x.org | xorg-server | >= 0 < 2:21.1.4-1 | 2:21.1.4-1 |
| x.org | xwayland | >= 0 < 2:22.1.3-1 | 2:22.1.3-1 |
| x.org | xwayland | >= 0 < 2:22.1.3-1 | 2:22.1.3-1 |
| x.org | xwayland | >= 0 < 2:22.1.3-1 | 2:22.1.3-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: usb: gadget: Fix use-after-free bug by not setting udc->dev.driver
vendor_redhat·2024-07-16·CVSS 5.5
CVE-2022-48838 [MEDIUM] kernel: usb: gadget: Fix use-after-free bug by not setting udc->dev.driver
kernel: usb: gadget: Fix use-after-free bug by not setting udc->dev.driver
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: Fix use-after-free bug by not setting udc->dev.driver
The syzbot fuzzer found a use-after-free bug:
BUG: KASAN: use-after-free in dev_uevent+0x712/0x780 drivers/base/core.c:2320
Read of size 8 at addr ffff88802b934098 by task udevd/3689
CPU: 2 PID: 3689 Comm: udevd Not tainted 5.17.0-rc4-syzkaller-00229-g4f12b742eb2b #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014
Call Trace:
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106
print_address_description.constprop.0.cold+0x8d/0x303 mm/kasan/report.c:255
__kasan_report mm/kasan/report.c:442 [inline]
kasan_report.cold+0x
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2022-07-12
CVE-2022-2319 X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
USN-5510-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
certain inputs. An attacker could use this issue to cause the server to
crash, resulting in a denial of service, or possibly execute arbitrary
code and escalate privileges.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2022-07-12
CVE-2022-2320 X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
certain inputs. An attacker could use this issue to cause the server to
crash, resulting in a denial of service, or possibly execute arbitrary
code and escalate privileges.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
xorg-x11-server: out-of-bounds access in ProcXkbSetDeviceInfo request handler of the Xkb extension
vendor_redhat·2022-07-12·CVSS 7.8
CVE-2022-2320 [HIGH] CWE-787 xorg-x11-server: out-of-bounds access in ProcXkbSetDeviceInfo request handler of the Xkb extension
xorg-x11-server: out-of-bounds access in ProcXkbSetDeviceInfo request handler of the Xkb extension
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and ex
Debian
CVE-2022-2320: xorg-server - A flaw was found in the Xorg-x11-server. The specific flaw exists within the han...
vendor_debian·2022·CVSS 7.8
CVE-2022-2320 [HIGH] CVE-2022-2320: xorg-server - A flaw was found in the Xorg-x11-server. The specific flaw exists within the han...
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
Scope: local
bookworm: resolved (fixed in 2:21.1.4-1)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u2)
forky: resolved (fixed in 2:21.1.4-1)
sid: resolved (fixed in 2:21.1.4-1)
trixie: resolved (fixed in 2:21.1.4-1)
GHSA
GHSA-w5qv-457x-4w67: A flaw was found in the Xorg-x11-server
ghsa_unreviewed·2022-09-02
CVE-2022-2320 [HIGH] CWE-787 GHSA-w5qv-457x-4w67: A flaw was found in the Xorg-x11-server
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
OSV
CVE-2022-2320: A flaw was found in the Xorg-x11-server
osv·2022-09-01·CVSS 7.8
CVE-2022-2320 [HIGH] CVE-2022-2320: A flaw was found in the Xorg-x11-server
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/freedesktop/xorg-xserver/commit/dd8caf39e9e15d8f302e54045dd08d8ebf1025dchttps://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/938https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/939https://lists.freedesktop.org/archives/xorg-announce/2022-July/003192.htmlhttps://security.gentoo.org/glsa/202210-30https://security.netapp.com/advisory/ntap-20221104-0003/https://www.zerodayinitiative.com/advisories/ZDI-22-963/https://github.com/freedesktop/xorg-xserver/commit/dd8caf39e9e15d8f302e54045dd08d8ebf1025dchttps://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/938https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/939https://lists.freedesktop.org/archives/xorg-announce/2022-July/003192.htmlhttps://security.gentoo.org/glsa/202210-30https://security.netapp.com/advisory/ntap-20221104-0003/https://www.zerodayinitiative.com/advisories/ZDI-22-963/
2022-09-01
Published