{"id":103807,"date":"2022-04-17T21:36:41","date_gmt":"2022-04-17T19:36:41","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland"},"modified":"2022-04-17T21:36:41","modified_gmt":"2022-04-17T19:36:41","slug":"uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland","title":{"rendered":"Vulnerabilities in swhkd, a hotkey manager for Wayland","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A series of vulnerabilities has been identified in swhkd (Simple Wayland HotKey Daemon), caused by improper handling of temporary files, command-line parameters, and Unix sockets. The program is written in Rust and processes hotkey presses in environments based on the Wayland protocol (file-configuration compatible analogous to the sxhkd process used in X11 environments).     <\/p>\n<p>The package includes an unprivileged process swhks, which handles hotkey actions, and a background process swhkd, running with root privileges and interacting with input devices at the uinput API level. A Unix socket is used to facilitate communication between swhks and swhkd. Through Polkit rules, any local user is allowed to run the process \/usr\/bin\/swhkd with root privileges and pass arbitrary parameters to it.    <\/p>\n<p>Identified vulnerabilities:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-27815 \u2014 saving the process PID to a file with a predictable name and in a directory writable by other users (\/tmp\/swhkd.pid). Any user can create the file \/tmp\/swhkd.pid and place the PID of an existing process into it, which will prevent swhkd from starting. In the absence of protection against creating symbolic links in \/tmp, this vulnerability can be exploited to create or overwrite files in any system directory (the PID is written to the file) or to determine the contents of any file on the system (swhkd outputs the entire contents of the PID file to stdout). It is noteworthy that in the released fix, the PID file was moved not to the \/run directory but to the \/etc directory (\/etc\/swhkd\/runtime\/swhkd_{uid}.pid), where it also does not belong.\n<li class=\"l\"> CVE-2022-27814 \u2014 by manipulating the command line parameter \"-c\", which is used to specify the configuration file, it is possible to determine the existence of any file on the system. For example, to check \/root\/.somefile, one could run \"pkexec \/usr\/bin\/swhkd -d -c \/root\/.somefile\" and if the file is absent, the error \"\/root\/.somefile doesn't exist\" will be displayed. As with the first vulnerability, the fix raises questions \u2014 the solution reduces to using an external utility \"cat\" (\"Command::new('\/bin\/cat').arg(path).output()\" to read the configuration file.).\n<li class=\"l\"> CVE-2022-27819 \u2014 this issue is also related to the use of the \"-c\" option, through which the configuration file is completely loaded and parsed without checking the size and type of the file. For example, to trigger a denial of service through memory exhaustion and generate parasitic input\/output, one could specify a block device when launching (\"pkexec \/usr\/bin\/swhkd -d -c \/dev\/sda\") or a character device that produces an infinite stream of data. The problem was resolved by dropping privileges before opening the file, but the fix was incomplete as only the user ID (UID) is dropped, while the group ID (GID) remains unchanged.\n<li class=\"l\"> CVE-2022-27818 \u2014 a Unix socket is created using the file \/tmp\/swhkd.sock, which is created in a publicly writable directory, leading to similar issues as the first vulnerability (any user can create \/tmp\/swhkd.sock and generate or intercept key press events).\n<li class=\"l\"> CVE-2022-27817 \u2014 Input events are accepted from all devices and in all sessions, meaning a user from another Wayland session or from the console can intercept key events when hotkeys are pressed by other users.\n<li class=\"l\"> CVE-2022-27816 \u2014 The swhks process, like swhkd, uses a PID file \/tmp\/swhks.pid in a publicly writable directory \/tmp. The issue is similar to the first vulnerability, but it is less severe, as swhks runs under an unprivileged user.      <\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57032\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 swhkd (Simple Wayland HotKey Daemon) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0441\u0435\u0440\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0438 unix-\u0441\u043e\u043a\u0435\u0442\u0430\u043c\u0438. \u041f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Rust \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 \u043d\u0430\u0436\u0430\u0442\u0438\u044f \u0433\u043e\u0440\u044f\u0447\u0438\u0445 \u043a\u043b\u0430\u0432\u0438\u0448 \u0432 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 Wayland (\u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u044b\u0439 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u0444\u0430\u0439\u043b\u043e\u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0430\u043d\u0430\u043b\u043e\u0433 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 sxhkd, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0432 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 X11). \u0412 \u0441\u043e\u0441\u0442\u0430\u0432 \u043f\u0430\u043a\u0435\u0442\u0430 \u0432\u0445\u043e\u0434\u0438\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103807","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 swhkd (Simple Wayland HotKey Daemon) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0441\u0435\u0440\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0438 unix-\u0441\u043e\u043a\u0435\u0442\u0430\u043c\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 swhkd, \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 \u0433\u043e\u0440\u044f\u0447\u0438\u0445 \u043a\u043b\u0430\u0432\u0438\u0448 \u0434\u043b\u044f Wayland | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 swhkd (Simple Wayland HotKey Daemon) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0441\u0435\u0440\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0438 unix-\u0441\u043e\u043a\u0435\u0442\u0430\u043c\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-04-17T19:36:41+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-04-17T19:36:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilities in swhkd, a hotkey manager for Wayland | ProHoster","description":"A series of vulnerabilities have been identified in swhkd (Simple Wayland HotKey Daemon) due to improper handling of temporary files, command-line parameters, and Unix sockets.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 swhkd, \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 \u0433\u043e\u0440\u044f\u0447\u0438\u0445 \u043a\u043b\u0430\u0432\u0438\u0448 \u0434\u043b\u044f Wayland | ProHoster","og:description":"\u0412 swhkd (Simple Wayland HotKey Daemon) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0441\u0435\u0440\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0438 unix-\u0441\u043e\u043a\u0435\u0442\u0430\u043c\u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-04-17T19:36:41+00:00","article:modified_time":"2022-04-17T19:36:41+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103807","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-25 10:28:44","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-04-17 19:37:39","updated":"2026-01-25 10:28:44","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/103807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=103807"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/103807\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=103807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=103807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=103807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}