• CVE-2022-2320

发布时间: 2024年7月12日

修改时间: 2025年4月13日

概要

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

CVSS v3 指标

NVD openEuler
CVSS评分 7.8 7.8
Attack Vector Local Local
Attack Complexity Low Low
Privileges Required Low Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality High High
Integrity High High
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-3124 xorg-x11-server-xwayland security update 2024年7月12日

影响产品

产品 状态
KY3.4-5A xorg-x11-server-xwayland Unaffected
KY3.5.2 xorg-x11-server-xwayland Fixed
V6 xorg-x11-server-xwayland Unaffected