CVE-2022-46341

medium
Published 2023-05-09 ยท Modified 2023-05-16
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description xorg-x11-server: XIPassiveUngrab out-of-bounds access Red Hat statement Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity. CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 6โ€ฆ

Description

xorg-x11-server: XIPassiveUngrab out-of-bounds access

Red Hat statement

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity.

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervnc-0:1.1.0-25.el6_10.13RHSA-2025:127512025-08-04T00:00:00Z
Red Hat Enterprise Linux 7tigervnc-0:1.8.0-23.el7_9RHSA-2023:00452023-01-09T00:00:00Z
Red Hat Enterprise Linux 7xorg-x11-server-0:1.20.4-21.el7_9RHSA-2023:00462023-01-09T00:00:00Z
Red Hat Enterprise Linux 8xorg-x11-server-Xwayland-0:21.1.3-10.el8RHSA-2023:28052023-05-16T00:00:00Z
Red Hat Enterprise Linux 8xorg-x11-server-0:1.20.11-15.el8RHSA-2023:28062023-05-16T00:00:00Z
Red Hat Enterprise Linux 8tigervnc-0:1.12.0-15.el8_8RHSA-2023:28302023-05-16T00:00:00Z
Red Hat Enterprise Linux 9xorg-x11-server-0:1.20.11-17.el9RHSA-2023:22482023-05-09T00:00:00Z
Red Hat Enterprise Linux 9xorg-x11-server-Xwayland-0:21.1.3-7.el9RHSA-2023:22492023-05-09T00:00:00Z
Red Hat Enterprise Linux 9tigervnc-0:1.12.0-13.el9_2RHSA-2023:22572023-05-09T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope

Apply commands

bash fix
Apply RHSA-2025:12751 for Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
yum update -y tigervnc
# or:
dnf upgrade -y tigervnc

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed tigervnc-server-1.12.0-13.el9_2.aarch64.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2:21.1.5-1
sid Fixed 2:21.1.5-1
forky Fixed 2:21.1.5-1
bullseye Fixed 2:1.20.11-1+deb11u4
bookworm Fixed 2:21.1.5-1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.