CVE-2022-3551
17.10.2022, 13:15
A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211052.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| x.org | x_server | 𝑥 < 21.1.6 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-server |
| ||||||||||||||
| xorg-server-hwe-16.04 |
| ||||||||||||||
| xorg-server-hwe-18.04 |
| ||||||||||||||
| xorg-server-lts-utopic |
| ||||||||||||||
| xorg-server-lts-vivid |
| ||||||||||||||
| xorg-server-lts-wily |
| ||||||||||||||
| xorg-server-lts-xenial |
| ||||||||||||||
| xwayland |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-x11-server |
| ||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-Xvfb |
| ||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-extra |
| ||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-sdk |
| ||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-wayland |
| ||||||||||||||||||||||||||||||||||||||||||
| xwayland |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||
|---|---|---|---|---|---|---|---|
| xorg-x11-server-Xdmx |
| ||||||
| xorg-x11-server-Xephyr |
| ||||||
| xorg-x11-server-Xnest |
| ||||||
| xorg-x11-server-Xorg |
| ||||||
| xorg-x11-server-Xvfb |
| ||||||
| xorg-x11-server-Xwayland |
| ||||||
| xorg-x11-server-common |
| ||||||
| xorg-x11-server-devel |
| ||||||
| xorg-x11-server-source |
|
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| xorg-x11-server-Xdmx |
| ||||
| xorg-x11-server-Xdmx-debuginfo |
| ||||
| xorg-x11-server-Xephyr |
| ||||
| xorg-x11-server-Xephyr-debuginfo |
| ||||
| xorg-x11-server-Xnest |
| ||||
| xorg-x11-server-Xnest-debuginfo |
| ||||
| xorg-x11-server-Xorg |
| ||||
| xorg-x11-server-Xorg-debuginfo |
| ||||
| xorg-x11-server-Xvfb |
| ||||
| xorg-x11-server-Xvfb-debuginfo |
| ||||
| xorg-x11-server-Xwayland |
| ||||
| xorg-x11-server-common |
| ||||
| xorg-x11-server-debuginfo |
| ||||
| xorg-x11-server-debugsource |
| ||||
| xorg-x11-server-devel |
| ||||
| xorg-x11-server-source |
|
Common Weakness Enumeration
- CWE-404 - Improper Resource Shutdown or ReleaseThe program does not release or incorrectly releases a resource before it is made available for re-use.
- CWE-401 - Missing Release of Memory after Effective LifetimeThe software does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
References