CVE-2022-2320
This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- x.org/x server
- Source
- secalert@redhat.com
References
- https://github.com/freedesktop/xorg-xserver/commit/dd8caf39e9e15d8f302e54045dd08d8ebf1025dcPatch, Third Party Advisory
- https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/938Patch, Third Party Advisory
- https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/939Patch, Third Party Advisory
- https://lists.freedesktop.org/archives/xorg-announce/2022-July/003192.htmlPatch, Third Party Advisory
- https://security.gentoo.org/glsa/202210-30Third Party Advisory
- https://security.netapp.com/advisory/ntap-20221104-0003/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-963/Third Party Advisory, VDB Entry
- https://github.com/freedesktop/xorg-xserver/commit/dd8caf39e9e15d8f302e54045dd08d8ebf1025dcPatch, Third Party Advisory
- https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/938Patch, Third Party Advisory
- https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/939Patch, Third Party Advisory
- https://lists.freedesktop.org/archives/xorg-announce/2022-July/003192.htmlPatch, Third Party Advisory
- https://security.gentoo.org/glsa/202210-30Third Party Advisory
- https://security.netapp.com/advisory/ntap-20221104-0003/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-963/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.