CVE-2022-46343
published 2022-12-14CVE-2022-46343: A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has…
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.37%
82.0th percentile
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xorg-server | < xorg-server 2:21.1.5-1 (bookworm) | xorg-server 2:21.1.5-1 (bookworm) |
| debian | xwayland | < xorg-server 2:21.1.5-1 (bookworm) | xorg-server 2:21.1.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 0 < 4.4.0-257.291 | 4.4.0-257.291 |
| x.org | x_server | — | — |
| x.org | xorg-server | >= 0 < 2:1.20.11-1+deb11u4 | 2:1.20.11-1+deb11u4 |
| x.org | xorg-server | >= 0 < 2:21.1.5-1 | 2:21.1.5-1 |
| x.org | xorg-server | >= 0 < 2:21.1.5-1 | 2:21.1.5-1 |
| x.org | xorg-server | >= 0 < 2:21.1.5-1 | 2:21.1.5-1 |
| x.org | xwayland | >= 0 < 2:22.1.6-1 | 2:22.1.6-1 |
| x.org | xwayland | >= 0 < 2:22.1.6-1 | 2:22.1.6-1 |
| x.org | xwayland | >= 0 < 2:22.1.6-1 | 2:22.1.6-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2023-02-16
CVE-2022-46344 X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
USN-5778-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Jan-Niklas Sohn discovered that X.Org X Server extensions contained
multiple security issues. An attacker could possibly use these issues to
cause the X Server to crash, execute arbitrary code, or escalate
privileges.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
xorg-x11-server: ScreenSaverSetAttributes use-after-free
vendor_redhat·2022-12-14·CVSS 8.8
CVE-2022-46343 [HIGH] CWE-416 xorg-x11-server: ScreenSaverSetAttributes use-after-free
xorg-x11-server: ScreenSaverSetAttributes use-after-free
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
A vulnerability was found in X.Org. This issue occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This flaw can lead to local privileges elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Statement: Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefo
BSD
OpenBSD 7.2 Errata 009: SECURITY FIX
bsd_advisories·2022-12-14·CVSS 8.8
CVE-2022-46340 [HIGH] OpenBSD 7.2 Errata 009: SECURITY FIX
OpenBSD 7.2 Errata 009: SECURITY FIX
009: SECURITY FIX: December 14, 2022
All architectures In X11 server fix local privileges elevation and remote code execution for ssh X forwarding sessions. This addresses CVE-2022-46340 CVE-2022-46341 CVE-2022-46342 CVE-2022-46343 CVE-2022-46344.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2022-12-14
CVE-2022-46341 X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
Jan-Niklas Sohn discovered that X.Org X Server extensions contained
multiple security issues. An attacker could possibly use these issues to
cause the X Server to crash, execute arbitrary code, or escalate
privileges.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
BSD
OpenBSD 7.1 Errata 015: SECURITY FIX
bsd_advisories·2022-12-14·CVSS 8.8
CVE-2022-46340 [HIGH] OpenBSD 7.1 Errata 015: SECURITY FIX
OpenBSD 7.1 Errata 015: SECURITY FIX
015: SECURITY FIX: December 14, 2022
All architectures In X11 server fix local privileges elevation and remote code execution for ssh X forwarding sessions. This addresses CVE-2022-46340 CVE-2022-46341 CVE-2022-46342 CVE-2022-46343 CVE-2022-46344.
Debian
CVE-2022-46343: xorg-server - A vulnerability was found in X.Org. This security flaw occurs because the handle...
vendor_debian·2022·CVSS 8.8
CVE-2022-46343 [HIGH] CVE-2022-46343: xorg-server - A vulnerability was found in X.Org. This security flaw occurs because the handle...
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Scope: local
bookworm: resolved (fixed in 2:21.1.5-1)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u4)
forky: resolved (fixed in 2:21.1.5-1)
sid: resolved (fixed in 2:21.1.5-1)
trixie: resolved (fixed in 2:21.1.5-1)
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-07-31·CVSS 5.5
CVE-2022-48619 linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
It was discovered that the device input subsystem in the Linux kernel did
not properly handle the case when an event code falls outside of a bitmap.
A local attacker could use this to cause a denial of service (system
crash). (CVE-2022-48619)
黄思聪 discovered that the NFC Controller Interface (NCI) implementation in
the Linux kernel did not properly handle certain memory allocation failure
conditions, leading to a null pointer dereference vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2023-46343)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through debugfs.
A privileged local attacker could
OSV
CVE-2022-46343: A vulnerability was found in X
osv·2022-12-14·CVSS 8.8
CVE-2022-46343 [HIGH] CVE-2022-46343: A vulnerability was found in X
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
GHSA
GHSA-cfjv-73gp-92j6: A vulnerability was found in X
ghsa_unreviewed·2022-12-14
CVE-2022-46343 [HIGH] CWE-416 GHSA-cfjv-73gp-92j6: A vulnerability was found in X
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-46343https://bugzilla.redhat.com/show_bug.cgi?id=2151758https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NELB7YDWRABYYBG4UPTHRBDTKJRV5M2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXDF2O5PPLE3SVAJJYUOSAD5QZ4TWQ2G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z67QC4C3I2FI2WRFIUPEHKC36J362MLA/https://security.gentoo.org/glsa/202305-30https://www.debian.org/security/2022/dsa-5304https://access.redhat.com/security/cve/CVE-2022-46343https://bugzilla.redhat.com/show_bug.cgi?id=2151758https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NELB7YDWRABYYBG4UPTHRBDTKJRV5M2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXDF2O5PPLE3SVAJJYUOSAD5QZ4TWQ2G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z67QC4C3I2FI2WRFIUPEHKC36J362MLA/https://security.gentoo.org/glsa/202305-30https://www.debian.org/security/2022/dsa-5304
2022-12-14
Published