CVE-2022-46342: Use After Free
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
Other sources
CVE-2022-46342/ZDI-CAN-19400: X.Org Server XvdiSelectVideoNotify use-after-free
The handler for the XvdiSelectVideoNotify request may write to memory after it has been freed.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46342?
CVE-2022-46342 is a vulnerability found in X.Org that allows local privilege elevation on systems where the X server is vulnerable.
What is the severity of CVE-2022-46342?
The severity of CVE-2022-46342 is high with a CVSS score of 8.8.
How does CVE-2022-46342 occur?
CVE-2022-46342 occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed.
Which systems are affected by CVE-2022-46342?
Systems running X.Org X Server versions 2:1.20.4 and earlier are affected by CVE-2022-46342.
How can I fix CVE-2022-46342?
To fix CVE-2022-46342, update the X.Org X Server to version 2:1.20.4-1+deb10u9 or higher.