CVE-2022-46342
published 2022-12-14CVE-2022-46342: A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been…
PriorityP349high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.30%
67.4th percentile
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xorg-server | < xorg-server 2:21.1.5-1 (bookworm) | xorg-server 2:21.1.5-1 (bookworm) |
| debian | xwayland | < xorg-server 2:21.1.5-1 (bookworm) | xorg-server 2:21.1.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| x.org | x_server | — | — |
| x.org | xorg-server | >= 0 < 2:1.20.11-1+deb11u4 | 2:1.20.11-1+deb11u4 |
| x.org | xorg-server | >= 0 < 2:21.1.5-1 | 2:21.1.5-1 |
| x.org | xorg-server | >= 0 < 2:21.1.5-1 | 2:21.1.5-1 |
| x.org | xorg-server | >= 0 < 2:21.1.5-1 | 2:21.1.5-1 |
| x.org | xwayland | >= 0 < 2:22.1.6-1 | 2:22.1.6-1 |
| x.org | xwayland | >= 0 < 2:22.1.6-1 | 2:22.1.6-1 |
| x.org | xwayland | >= 0 < 2:22.1.6-1 | 2:22.1.6-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2023-02-16
CVE-2022-46344 X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
USN-5778-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Jan-Niklas Sohn discovered that X.Org X Server extensions contained
multiple security issues. An attacker could possibly use these issues to
cause the X Server to crash, execute arbitrary code, or escalate
privileges.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
BSD
OpenBSD 7.2 Errata 009: SECURITY FIX
bsd_advisories·2022-12-14·CVSS 8.8
CVE-2022-46340 [HIGH] OpenBSD 7.2 Errata 009: SECURITY FIX
OpenBSD 7.2 Errata 009: SECURITY FIX
009: SECURITY FIX: December 14, 2022
All architectures In X11 server fix local privileges elevation and remote code execution for ssh X forwarding sessions. This addresses CVE-2022-46340 CVE-2022-46341 CVE-2022-46342 CVE-2022-46343 CVE-2022-46344.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2022-12-14
CVE-2022-46341 X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
Jan-Niklas Sohn discovered that X.Org X Server extensions contained
multiple security issues. An attacker could possibly use these issues to
cause the X Server to crash, execute arbitrary code, or escalate
privileges.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
xorg-x11-server: XvdiSelectVideoNotify use-after-free
vendor_redhat·2022-12-14·CVSS 8.8
CVE-2022-46342 [HIGH] CWE-416 xorg-x11-server: XvdiSelectVideoNotify use-after-free
xorg-x11-server: XvdiSelectVideoNotify use-after-free
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
A vulnerability was found in X.Org. This flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This flaw can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Statement: Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity.
Package: xorg-x
BSD
OpenBSD 7.1 Errata 015: SECURITY FIX
bsd_advisories·2022-12-14·CVSS 8.8
CVE-2022-46340 [HIGH] OpenBSD 7.1 Errata 015: SECURITY FIX
OpenBSD 7.1 Errata 015: SECURITY FIX
015: SECURITY FIX: December 14, 2022
All architectures In X11 server fix local privileges elevation and remote code execution for ssh X forwarding sessions. This addresses CVE-2022-46340 CVE-2022-46341 CVE-2022-46342 CVE-2022-46343 CVE-2022-46344.
Debian
CVE-2022-46342: xorg-server - A vulnerability was found in X.Org. This security flaw occurs because the handle...
vendor_debian·2022·CVSS 8.8
CVE-2022-46342 [HIGH] CVE-2022-46342: xorg-server - A vulnerability was found in X.Org. This security flaw occurs because the handle...
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
Scope: local
bookworm: resolved (fixed in 2:21.1.5-1)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u4)
forky: resolved (fixed in 2:21.1.5-1)
sid: resolved (fixed in 2:21.1.5-1)
trixie: resolved (fixed in 2:21.1.5-1)
OSV
CVE-2022-46342: A vulnerability was found in X
osv·2022-12-14·CVSS 8.8
CVE-2022-46342 [HIGH] CVE-2022-46342: A vulnerability was found in X
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
GHSA
GHSA-5hp7-2mv5-p69r: A vulnerability was found in X
ghsa_unreviewed·2022-12-14
CVE-2022-46342 [HIGH] CWE-416 GHSA-5hp7-2mv5-p69r: A vulnerability was found in X
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-46342https://bugzilla.redhat.com/show_bug.cgi?id=2151757https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NELB7YDWRABYYBG4UPTHRBDTKJRV5M2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXDF2O5PPLE3SVAJJYUOSAD5QZ4TWQ2G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z67QC4C3I2FI2WRFIUPEHKC36J362MLA/https://security.gentoo.org/glsa/202305-30https://www.debian.org/security/2022/dsa-5304https://access.redhat.com/security/cve/CVE-2022-46342https://bugzilla.redhat.com/show_bug.cgi?id=2151757https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NELB7YDWRABYYBG4UPTHRBDTKJRV5M2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXDF2O5PPLE3SVAJJYUOSAD5QZ4TWQ2G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z67QC4C3I2FI2WRFIUPEHKC36J362MLA/https://security.gentoo.org/glsa/202305-30https://www.debian.org/security/2022/dsa-5304
2022-12-14
Published