Bug 2151757 (CVE-2022-46342) - CVE-2022-46342 xorg-x11-server: XvdiSelectVideoNotify use-after-free
Summary: CVE-2022-46342 xorg-x11-server: XvdiSelectVideoNotify use-after-free
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-46342
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2151784 2151785 2151786 2151788 2153119 2154211 2154212 2154225 2154226 2151787 2153120 2153121 2153123 2154262
Blocks: 2151201
TreeView+ depends on / blocked
 
Reported: 2022-12-08 04:50 UTC by Sandipan Roy
Modified: 2023-03-03 08:56 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in X.Org. This flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This flaw can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Clone Of:
Environment:
Last Closed: 2023-01-11 10:32:18 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:0045 0 None None None 2023-01-09 14:53:12 UTC
Red Hat Product Errata RHSA-2023:0046 0 None None None 2023-01-09 14:53:36 UTC

Description Sandipan Roy 2022-12-08 04:50:56 UTC
CVE-2022-46342/ZDI-CAN-19400: X.Org Server XvdiSelectVideoNotify
use-after-free

The handler for the XvdiSelectVideoNotify request may write to memory
after it has been freed.

Comment 2 Sandipan Roy 2022-12-08 06:34:59 UTC
Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore Red Hat Enterprise Linux 8 and 9 have been rated with a moderate severity.

Comment 4 Sandipan Roy 2022-12-14 04:44:41 UTC
Created xorg-x11-server tracking bugs for this issue:

Affects: fedora-36 [bug 2153121]
Affects: fedora-37 [bug 2153123]


Created xorg-x11-server-Xwayland tracking bugs for this issue:

Affects: fedora-36 [bug 2153119]
Affects: fedora-37 [bug 2153120]

Comment 5 Sandipan Roy 2022-12-16 09:59:10 UTC
Created tigervnc tracking bugs for this issue:

Affects: fedora-36 [bug 2154211]
Affects: fedora-37 [bug 2154212]

Comment 8 errata-xmlrpc 2023-01-09 14:53:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2023:0045 https://access.redhat.com/errata/RHSA-2023:0045

Comment 9 errata-xmlrpc 2023-01-09 14:53:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2023:0046 https://access.redhat.com/errata/RHSA-2023:0046

Comment 10 Product Security DevOps Team 2023-01-11 10:32:17 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-46342


Note You need to log in before you can comment on or make changes to this bug.