CVE-2022-4283
14.12.2022, 21:15
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.Enginsight
Vendor | Product | Version |
---|---|---|
x.org | xorg-server | 1.20.4 |
redhat | enterprise_linux | 6.0 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
xorg-server |
| ||||||||||||||
xorg-server-hwe-16.04 |
| ||||||||||||||
xorg-server-hwe-18.04 |
| ||||||||||||||
xorg-server-lts-utopic |
| ||||||||||||||
xorg-server-lts-vivid |
| ||||||||||||||
xorg-server-lts-wily |
| ||||||||||||||
xorg-server-lts-xenial |
| ||||||||||||||
xwayland |
|
Common Weakness Enumeration
References