Description
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Related CPE's
o
fedoraproject
fedora
o
redhat
enterprise_linux
o
redhat
enterprise_linux_aus
o
redhat
enterprise_linux_eus
o
redhat
enterprise_linux_for_ibm_z_systems
o
redhat
enterprise_linux_for_ibm_z_systems_eus
o
redhat
enterprise_linux_for_power_little_endian
o
redhat
enterprise_linux_for_power_little_endian_eus
o
redhat
enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
o
redhat
enterprise_linux_server_tus
References
https://bugzilla.redhat.com/show_bug.cgi?id=2165995
https://lists.x.org/archives/xorg-announce/2023-February/003320.html
https://bugzilla.redhat.com/show_bug.cgi?id=2165995
https://lists.x.org/archives/xorg-announce/2023-February/003320.html
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 · High
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2023-03-27T21:15:10.193
2 years agoLast modified
2025-02-24T18:15:16.550
4 months ago