X.org Server xkb.c _GetCountedString buffer overflow
Published Oct 17, 2022
8.8
HIGHCVSS 3.1
EPSS 1.58%
Description
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
Affected products
Configuration 2
- 10.0
- 11.0
Configuration 3
- 35
- 36
- 37
No data.
Red Hat Enterprise Linux 7
xorg-x11-server-0:1.20.4-19.el7_9
Fixed · RHSA-2022:8491
Red Hat Enterprise Linux 8
xorg-x11-server-0:1.20.11-15.el8
Fixed · RHSA-2023:2806
Red Hat Enterprise Linux 8
xorg-x11-server-Xwayland-0:21.1.3-10.el8
Fixed · RHSA-2023:2805
Red Hat Enterprise Linux 9
xorg-x11-server-0:1.20.11-17.el9
Fixed · RHSA-2023:2248
Red Hat Enterprise Linux 9
xorg-x11-server-Xwayland-0:21.1.3-7.el9
Fixed · RHSA-2023:2249
Red Hat Enterprise Linux 6
xorg-x11-server
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | xorg-x11-server-0:1.20.4-19.el7_9 | Fixed | RHSA-2022:8491 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-0:1.20.11-15.el8 | Fixed | RHSA-2023:2806 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland-0:21.1.3-10.el8 | Fixed | RHSA-2023:2805 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-0:1.20.11-17.el9 | Fixed | RHSA-2023:2248 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland-0:21.1.3-7.el9 | Fixed | RHSA-2023:2249 |
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore Red Hat Enterprise Linux 8 and 9 have been rated with a moderate severity.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-3550 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2140698 Issue Tracking
- https://cgit.freedesktop.org/xorg/xserver/commit/?id=11beef0b7f1ed290348e45618e5fa0d2bffcb72e Mailing ListPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42916 Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00012.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QTPFVGYTOY4EWTJEBH3YGDTTU57FZAK/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOEDFBYPSE3EMVHTEFCVEJD2R2Y5F2A5/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXZZ6JBDBVBYPDI6DUTY6N36GNW37YHK/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X7W3NXSYK4P3XCZQBI3U6UWP4DPZIMRZ/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3550
- https://security.gentoo.org/glsa/202305-30 vendor-advisory
- https://vuldb.com/?id.211051 Third Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2022-3550
- https://www.debian.org/security/2022/dsa-5278 vendor-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.