Null pointer dereference in libxkbcommon - CVE-2018-15862
Published: November 16, 2018
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer usage condition by the LookupModMask function, as defined in the xkbcomp/expr.c source code file. A local attacker can submit a specially crafted keymap file that submits malicious input to an affected system with invalid virtual modifiers, trigger NULL pointer dereference and cause the application to crash.
Affected software
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
libxkbcommon-x11-devel
libxkbcommon-devel
libxkbcommon-debugsource
libxkbcommon0
libxkbcommon-x11-0
libxkbcommon0-debuginfo
libxkbcommon-x11-0-debuginfo
libxkbcommon0-32bit
libxkbcommon0-debuginfo-32bit
libxkbcommon-x11-0-32bit
libxkbcommon-x11-0-debuginfo-32bit
How to mitigate CVE-2018-15862
libxkbcommon-x11-devel - update to 0.6.1-9.3.1
libxkbcommon-devel - update to 0.6.1-9.3.1
libxkbcommon-debugsource - update to 0.6.1-9.3.1
libxkbcommon0 - update to 0.6.1-9.3.1
libxkbcommon-x11-0 - update to 0.6.1-9.3.1
libxkbcommon0-debuginfo - update to 0.6.1-9.3.1
libxkbcommon-x11-0-debuginfo - update to 0.6.1-9.3.1
libxkbcommon0-32bit - update to 0.6.1-9.3.1
libxkbcommon0-debuginfo-32bit - update to 0.6.1-9.3.1
libxkbcommon-x11-0-32bit - update to 0.6.1-9.3.1
libxkbcommon-x11-0-debuginfo-32bit - update to 0.6.1-9.3.1