Advisories ยป MGASA-2022-0256

Updated x11-server packages fix security vulnerabilities

Publication date: 13 Jul 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-2319 , CVE-2022-2320

Description

Updated x11-server packages fix security vulnerabilities:

ProcXkbSetGeometry Out-Of-Bounds Access.
The handler for the ProcXkbSetGeometry request of the Xkb extension does
not properly validate the request length leading to out of bounds memory
write (CVE-2022-2319).

ProcXkbSetDeviceInfo Out-Of-Bounds Access.
The handler for the ProcXkbSetDeviceInfo request of the Xkb extension
does not properly validate the request length leading to out of bounds
memory write (CVE-2022-2320).
                

References

SRPMS

8/core