A corrective release of the Pixman library 0.42.2 has been published, which is used for low-level graphics rendering in many open-source projects, including X.Org, Cairo, Firefox, and Wayland-based composite managers. The new version fixes a critical vulnerability (CVE-2022-44638) that leads to a buffer overflow when processing pixel data with parameters that cause integer overflow.
Researchers have released a prototype exploit demonstrating the potential for controlled data overwriting beyond the allocated buffer. It cannot be ruled out that this vulnerability could be used to facilitate the execution of attacker's code. You can track the release of fixes by distributions on the following pages: Debian, RHEL, Fedora, SUSE, Ubuntu, Arch Linux, OpenBSD, FreeBSD, NetBSD.
Source: opennet.ru
