xorg-x11-server: XvdiSelectVideoNotify use-after-free
Published Dec 14, 2022
8.8
HIGHCVSS 3.1
EPSS 1.36%
Description
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
Affected products
- Vendor n/a Product Xorg-X11-Server Defaultn/a
- Version xorg-x11-server-1.20.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Xorg-X11-Server | n/a |
|
Configuration 1
Running on/with
- 6.0
- 7.0
- 8.0
- 9.0
Configuration 2
- 36
- 37
Configuration 3
- 11.0
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
tigervnc-0:1.1.0-25.el6_10.13
Fixed · RHSA-2025:12751
Red Hat Enterprise Linux 7
tigervnc-0:1.8.0-23.el7_9
Fixed · RHSA-2023:0045
Red Hat Enterprise Linux 7
xorg-x11-server-0:1.20.4-21.el7_9
Fixed · RHSA-2023:0046
Red Hat Enterprise Linux 8
tigervnc-0:1.12.0-15.el8_8
Fixed · RHSA-2023:2830
Red Hat Enterprise Linux 8
xorg-x11-server-0:1.20.11-15.el8
Fixed · RHSA-2023:2806
Red Hat Enterprise Linux 8
xorg-x11-server-Xwayland-0:21.1.3-10.el8
Fixed · RHSA-2023:2805
Red Hat Enterprise Linux 9
tigervnc-0:1.12.0-13.el9_2
Fixed · RHSA-2023:2257
Red Hat Enterprise Linux 9
xorg-x11-server-0:1.20.11-17.el9
Fixed · RHSA-2023:2248
Red Hat Enterprise Linux 9
xorg-x11-server-Xwayland-0:21.1.3-7.el9
Fixed · RHSA-2023:2249
Red Hat Enterprise Linux 6
xorg-x11-server
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | tigervnc-0:1.1.0-25.el6_10.13 | Fixed | RHSA-2025:12751 |
| Red Hat Enterprise Linux 7 | tigervnc-0:1.8.0-23.el7_9 | Fixed | RHSA-2023:0045 |
| Red Hat Enterprise Linux 7 | xorg-x11-server-0:1.20.4-21.el7_9 | Fixed | RHSA-2023:0046 |
| Red Hat Enterprise Linux 8 | tigervnc-0:1.12.0-15.el8_8 | Fixed | RHSA-2023:2830 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-0:1.20.11-15.el8 | Fixed | RHSA-2023:2806 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland-0:21.1.3-10.el8 | Fixed | RHSA-2023:2805 |
| Red Hat Enterprise Linux 9 | tigervnc-0:1.12.0-13.el9_2 | Fixed | RHSA-2023:2257 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-0:1.20.11-17.el9 | Fixed | RHSA-2023:2248 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland-0:21.1.3-7.el9 | Fixed | RHSA-2023:2249 |
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-46342 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2151757 Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NELB7YDWRABYYBG4UPTHRBDTKJRV5M2/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXDF2O5PPLE3SVAJJYUOSAD5QZ4TWQ2G/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z67QC4C3I2FI2WRFIUPEHKC36J362MLA/ vendor-advisoryMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-46342
- https://security.gentoo.org/glsa/202305-30
- https://www.cve.org/CVERecord?id=CVE-2022-46342
- https://www.debian.org/security/2022/dsa-5304 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-46342 | Third Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2151757 | Issue TrackingThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NELB7YDWRABYYBG4UPTHRBDTKJRV5M2/ | vendor-advisoryMailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXDF2O5PPLE3SVAJJYUOSAD5QZ4TWQ2G/ | vendor-advisoryMailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z67QC4C3I2FI2WRFIUPEHKC36J362MLA/ | vendor-advisoryMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-46342 | ||
| https://security.gentoo.org/glsa/202305-30 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-46342 | ||
| https://www.debian.org/security/2022/dsa-5304 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.