Null pointer dereference in libxkbcommon - CVE-2018-15855

 

Null pointer dereference in libxkbcommon - CVE-2018-15855

Published: November 13, 2018


Vulnerability identifier: #VU15815
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15855
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to unchecked NULL pointer usage condition when the XkbFile is mishandled. A local attacker can submit a specially crafted keymap file that submits malicious input, trigger NULL pointer dereference and cause the application to crash.


Affected software

libxkbcommon
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
libxkbcommon-x11-devel
libxkbcommon-devel
libxkbcommon-debugsource
libxkbcommon0
libxkbcommon-x11-0
libxkbcommon0-debuginfo
libxkbcommon-x11-0-debuginfo
libxkbcommon0-32bit
libxkbcommon0-debuginfo-32bit
libxkbcommon-x11-0-32bit
libxkbcommon-x11-0-debuginfo-32bit

How to mitigate CVE-2018-15855

Update to version 0.8.1.

libxkbcommon - update to 0.8.1
libxkbcommon-x11-devel - update to 0.6.1-9.3.1
libxkbcommon-devel - update to 0.6.1-9.3.1
libxkbcommon-debugsource - update to 0.6.1-9.3.1
libxkbcommon0 - update to 0.6.1-9.3.1
libxkbcommon-x11-0 - update to 0.6.1-9.3.1
libxkbcommon0-debuginfo - update to 0.6.1-9.3.1
libxkbcommon-x11-0-debuginfo - update to 0.6.1-9.3.1
libxkbcommon0-32bit - update to 0.6.1-9.3.1
libxkbcommon0-debuginfo-32bit - update to 0.6.1-9.3.1
libxkbcommon-x11-0-32bit - update to 0.6.1-9.3.1
libxkbcommon-x11-0-debuginfo-32bit - update to 0.6.1-9.3.1

External References

Related Security Bulletins