REDHAT-BUG-2317233: High severity x.org xserver vulnerability
The XkbSetCompatMap() function attempts to resize the syminterpret buffer. However, it didn't update its size properly. It updated numsi only, without sizesi: https://gitlab.freedesktop.org/xorg/xserver/-/blob/cdb4d5648a818a8e8ab282341be37109589229ab/xkb/xkb.c#L2998
The exploit uses bitmap to achieve the arbitrary read and write. It leads to LPE for some distributions (xorg in debian xfce is run as root under specific display driver) and RCE for ssh x11 forwarding environment.
The exploit doesn't work if the OS installed on vmware and default virtualbox. It works on virtualbox with VBoxVGA graphic controller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2317233?
The severity of REDHAT-BUG-2317233 is classified as medium due to potential memory corruption risks.
How do I fix REDHAT-BUG-2317233?
To fix REDHAT-BUG-2317233, apply the latest software updates provided by your Linux distribution vendor.
Which software is affected by REDHAT-BUG-2317233?
REDHAT-BUG-2317233 affects the X.Org X Server software.
What are the potential consequences of REDHAT-BUG-2317233?
The potential consequences of REDHAT-BUG-2317233 include memory corruption, which may lead to crashes or arbitrary code execution.
Is there a workaround for REDHAT-BUG-2317233?
There is no documented workaround for REDHAT-BUG-2317233, so applying updates is crucial.