CVE-2022-46344: High severity x.org xserver vulnerability
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Other sources
CVE-2022-46344/ZDI-CAN-19405: X.Org Server XIChangeProperty out-of-bounds access
The handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46344?
CVE-2022-46344 is a vulnerability found in X.Org that can lead to local privilege escalation due to a length-validation issue in the XIChangeProperty request handler.
How severe is the CVE-2022-46344 vulnerability?
CVE-2022-46344 has a severity score of 8.8, which is considered high.
Which software versions are affected by CVE-2022-46344?
The vulnerability affects xorg-server versions up to and including 2:1.20.4, xorg-server versions 2:1.20.4-1+deb10u4, xorg-server versions 2:1.20.11-1+deb11u6, xorg-server versions 2:21.1.7-3, and xorg-server versions 2:21.1.8-1.
How can I fix the CVE-2022-46344 vulnerability?
To fix the CVE-2022-46344 vulnerability, update your xorg-server software to the recommended versions: 2:1.20.4-1+deb10u9, 2:1.20.11-1+deb11u6, 2:21.1.7-3, or 2:21.1.8-1.
Where can I find more information about the CVE-2022-46344 vulnerability?
You can find more information about the CVE-2022-46344 vulnerability in the following references: [Link 1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2153137), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2153138), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2153135).