Improper input validation in libxkbcommon - CVE-2018-15857

 

Improper input validation in libxkbcommon - CVE-2018-15857

Published: November 13, 2018


Vulnerability identifier: #VU15817
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15857
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an invalid-free error in the ExprAppendMultiKeysymList function, as defined in the xkbcomp/ast-build.c source code file. A local attacker can submit a specially crafted keymap file that submits malicious input and cause the application to crash.


Affected software

libxkbcommon
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
libxkbcommon-x11-devel
libxkbcommon-devel
libxkbcommon-debugsource
libxkbcommon0
libxkbcommon-x11-0
libxkbcommon0-debuginfo
libxkbcommon-x11-0-debuginfo
libxkbcommon0-32bit
libxkbcommon0-debuginfo-32bit
libxkbcommon-x11-0-32bit
libxkbcommon-x11-0-debuginfo-32bit

How to mitigate CVE-2018-15857

Update to version 0.8.1.

libxkbcommon - update to 0.8.1
libxkbcommon-x11-devel - update to 0.6.1-9.3.1
libxkbcommon-devel - update to 0.6.1-9.3.1
libxkbcommon-debugsource - update to 0.6.1-9.3.1
libxkbcommon0 - update to 0.6.1-9.3.1
libxkbcommon-x11-0 - update to 0.6.1-9.3.1
libxkbcommon0-debuginfo - update to 0.6.1-9.3.1
libxkbcommon-x11-0-debuginfo - update to 0.6.1-9.3.1
libxkbcommon0-32bit - update to 0.6.1-9.3.1
libxkbcommon0-debuginfo-32bit - update to 0.6.1-9.3.1
libxkbcommon-x11-0-32bit - update to 0.6.1-9.3.1
libxkbcommon-x11-0-debuginfo-32bit - update to 0.6.1-9.3.1

External References

Related Security Bulletins