Null pointer dereference in libxkbcommon - CVE-2018-15858
Published: November 16, 2018
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer usage condition by the CopyKeyAliasesToKeymap function, as defined in the xkbcomp/keycodes.c source code file. A local attacker can submit a specially crafted keymap file that submits malicious input, trigger NULL pointer dereference and cause the application to crash.
Affected software
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Opensuse
libxkbcommon-x11-devel
libxkbcommon-devel
libxkbcommon-debugsource
libxkbcommon0
libxkbcommon-x11-0
libxkbcommon0-debuginfo
libxkbcommon-x11-0-debuginfo
libxkbcommon0-32bit
libxkbcommon0-debuginfo-32bit
libxkbcommon-x11-0-32bit
libxkbcommon-x11-0-debuginfo-32bit
How to mitigate CVE-2018-15858
libxkbcommon-x11-devel - update to 0.6.1-9.3.1
libxkbcommon-devel - update to 0.6.1-9.3.1
libxkbcommon-debugsource - update to 0.6.1-9.3.1
libxkbcommon0 - update to 0.6.1-9.3.1
libxkbcommon-x11-0 - update to 0.6.1-9.3.1
libxkbcommon0-debuginfo - update to 0.6.1-9.3.1
libxkbcommon-x11-0-debuginfo - update to 0.6.1-9.3.1
libxkbcommon0-32bit - update to 0.6.1-9.3.1
libxkbcommon0-debuginfo-32bit - update to 0.6.1-9.3.1
libxkbcommon-x11-0-32bit - update to 0.6.1-9.3.1
libxkbcommon-x11-0-debuginfo-32bit - update to 0.6.1-9.3.1