CVE-2022-4283: Use After Free
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Other sources
CVE-2022-4283/ZDI-CAN-19530: X.Org Server XkbGetKbdByName use-after-free
The XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-4283.
What is the severity level of CVE-2022-4283?
The severity level of CVE-2022-4283 is high.
Which software is affected by CVE-2022-4283?
The software affected by CVE-2022-4283 includes X.org Xorg-server, Fedoraproject Fedora, Redhat Enterprise Linux, and Debian Debian Linux.
Is there a fix available for CVE-2022-4283?
Yes, there are fixes available for CVE-2022-4283. Please refer to the references for more information.
What is the Common Weakness Enumeration (CWE) ID of CVE-2022-4283?
The Common Weakness Enumeration (CWE) ID of CVE-2022-4283 is 416.