Update of X.Org Server 21.1.5 and xwayland 22.1.6 addressing 6 vulnerabilities

Corrective releases of X.Org Server 21.1.5 and xwayland 22.1.6 have been published. The DDX component (Device-Dependent X) enables the launch of X.Org Server to run X11 applications in Wayland-based environments. The new versions fix 6 vulnerabilities that could potentially be exploited to escalate privileges in systems where the X server runs with root rights, as well as for remote code execution in configurations where access uses X11 session forwarding via SSH.

  • CVE-2022-46340 — Stack overflow when processing XTestSwapFakeInput requests with data larger than 32 bytes in the GenericEvents field.
  • CVE-2022-46341 — Out of bounds memory access when handling XIPassiveUngrab requests triggered with large key or button code values.
  • CVE-2022-46342 — Use-after-free vulnerability through manipulation of XvdiSelectVideoNotify requests.
  • CVE-2022-46343 — Use-after-free vulnerability through manipulation of ScreenSaverSetAttributes requests.
  • CVE-2022-46344 — Out of bounds access when processing XIChangeProperty requests with large parameters.
  • CVE-2022-46283 — Use-after-free vulnerability through manipulation of XkbGetKbdByName requests.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster