CVE-2022-46343

NameCVE-2022-46343
DescriptionA vulnerability was found in X.Org. This issue occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This flaw can lead to local privileges elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3256-1, DSA-5304-1
Debian Bugs1026071

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xorg-server (PTS)buster2:1.20.4-1+deb10u4vulnerable
buster (security)2:1.20.4-1+deb10u7fixed
bullseye2:1.20.11-1+deb11u3vulnerable
bullseye (security)2:1.20.11-1+deb11u4fixed
bookworm, sid2:21.1.6-1fixed
xwayland (PTS)bookworm, sid2:22.1.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xorg-serversourcebuster2:1.20.4-1+deb10u7DLA-3256-1
xorg-serversourcebullseye2:1.20.11-1+deb11u4DSA-5304-1
xorg-serversource(unstable)2:21.1.5-11026071
xwaylandsource(unstable)2:22.1.6-1

Notes

https://lists.x.org/archives/xorg-announce/2022-December/003302.html
https://gitlab.freedesktop.org/xorg/xserver/commit/842ca3ccef100ce010d1d8f5f6d6cc1915055900

Search for package or bug name: Reporting problems