Updated x11-server packages fix security vulnerabilities:
ProcXkbSetGeometry Out-Of-Bounds Access.
The handler for the ProcXkbSetGeometry request of the Xkb extension does
not properly validate the request length leading to out of bounds memory
write (CVE-2022-2319).
ProcXkbSetDeviceInfo Out-Of-Bounds Access.
The handler for the ProcXkbSetDeviceInfo request of the Xkb extension
does not properly validate the request length leading to out of bounds
memory write (CVE-2022-2320).
- https://bugs.mageia.org/show_bug.cgi?id=30628
- https://lists.x.org/archives/xorg/2022-July/061035.html
- https://www.cve.org/CVERecord?id=CVE-2022-2319
- https://www.cve.org/CVERecord?id=CVE-2022-2320
- 8/core/x11-server-1.20.14-3.mga8
Get the latest Linux and open source security news straight to your inbox.