First published: Sat Aug 25 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libxkbcommon | <0.8.1 | 0.8.1 |
debian/libxkbcommon | 1.0.3-2 1.5.0-1 1.6.0-1 | |
libxkbcommon-x11 | <0.8.1 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15854 has a severity rating that indicates it allows local attackers to crash the xkbcommon parser.
To fix CVE-2018-15854, update libxkbcommon to version 0.8.1 or later for Red Hat, or to versions 1.0.3-2, 1.5.0-1, or 1.6.0-1 for Debian.
CVE-2018-15854 affects all versions of libxkbcommon prior to 0.8.1.
CVE-2018-15854 can be exploited by local attackers who supply a crafted keymap file to trigger a NULL pointer dereference.
Yes, Ubuntu versions 14.04, 16.04, and 18.04 are among the operating systems vulnerable to CVE-2018-15854.