Lucene search

K
cvelistRedhatCVELIST:CVE-2022-2320
HistorySep 01, 2022 - 12:00 a.m.

CVE-2022-2320

2022-09-0100:00:00
CWE-787
redhat
www.cve.org
xorg-x11-server
procxkbsetdeviceinfo
privilege escalation

8.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.7%

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "xorg-x11-server",
    "versions": [
      {
        "version": "xorg-x11-server 21.1",
        "status": "affected"
      }
    ]
  }
]