Red Hat Bugzilla – Bug 1623033
CVE-2018-15864 libxkbcommon: NULL pointer dereference in resolve_keysym resulting in a crash
Last modified: 2018-10-26 07:29:45 EDT
Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because a map access attempt can occur for a map that was never created. Upstream patch: https://github.com/xkbcommon/libxkbcommon/commit/a8ea7a1d3daa7bdcb877615ae0a252c189153bd2 References: https://lists.freedesktop.org/archives/wayland-devel/2018-August/039243.html