First published: Thu Dec 08 2022(Updated: )
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
X.Org X Server | =1.20.4 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Debian Debian Linux | =11.0 | |
debian/xorg-server | <=2:1.20.4-1+deb10u4 | 2:1.20.4-1+deb10u12 2:1.20.11-1+deb11u6 2:1.20.11-1+deb11u10 2:21.1.7-3+deb12u2 2:21.1.7-3+deb12u4 2:21.1.10-1 |
debian/xwayland | 2:22.1.9-1 2:23.2.3-1 | |
All of | ||
X.Org X Server | =1.20.4 | |
Any of | ||
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46342 is a vulnerability found in X.Org that allows local privilege elevation on systems where the X server is vulnerable.
The severity of CVE-2022-46342 is high with a CVSS score of 8.8.
CVE-2022-46342 occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed.
Systems running X.Org X Server versions 2:1.20.4 and earlier are affected by CVE-2022-46342.
To fix CVE-2022-46342, update the X.Org X Server to version 2:1.20.4-1+deb10u9 or higher.