Memory leak in X.org Server - CVE-2022-3553

 

Memory leak in X.org Server - CVE-2022-3553

Published: October 18, 2022 / Updated: February 7, 2023


Vulnerability identifier: #VU68417
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3553
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform DoS attack on the target system.

The vulnerability exists due memory leak within the xquartz component in hw/xquartz/X11Controller.m. A local user can force the application to leak memory and perform denial of service attack.


Affected software

X.org Server
Gentoo Linux
Slackware Linux
openEuler
tigervnc
xorg-x11-server
xorg-x11-server-devel
xorg-x11-server-debuginfo
xorg-x11-server-Xephyr
xorg-x11-server-debugsource
xorg-x11-server-help
xorg-server
xorg-server-xephyr
xorg-server-xnest
xorg-server-xvfb
xorg-server-xwayland
x11-base/xorg-server
x11-base/xwayland

How to mitigate CVE-2022-3553

Install update from vendor's website.

X.org Server - update to 21.1.5
tigervnc - addressed in versions 1.12.0, 1.13.1
xorg-x11-server - update to 1.20.8-12
xorg-x11-server-devel - update to 1.20.8-12
xorg-x11-server-debuginfo - update to 1.20.8-12
xorg-x11-server-Xephyr - update to 1.20.8-12
xorg-x11-server-debugsource - update to 1.20.8-12
xorg-x11-server-help - update to 1.20.8-12
xorg-server - update to 1.20.14
xorg-server-xephyr - update to 1.20.14
xorg-server-xnest - update to 1.20.14
xorg-server-xvfb - update to 1.20.14
xorg-server-xwayland - update to 21.1.4
x11-base/xorg-server - update to 21.1.8
x11-base/xwayland - update to 23.1.1

External References

Related Security Bulletins