Bugzilla – Bug 1204412
VUL-0: CVE-2022-3550: xwayland,xorg-x11-server: out of bounds read/write in _GetCountedString()
Last modified: 2023-01-09 09:39:50 UTC
CVE-2022-3550 A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3550 https://www.cve.org/CVERecord?id=CVE-2022-3550 https://cgit.freedesktop.org/xorg/xserver/commit/?id=11beef0b7f1ed290348e45618e5fa0d2bffcb72e https://vuldb.com/?id.211051
Affected: - SUSE:SLE-11-SP3:Update/xorg-x11-server - SUSE:SLE-12-SP2:Update/xorg-x11-server - SUSE:SLE-12-SP4:Update/xorg-x11-server - SUSE:SLE-12-SP5:Update/xorg-x11-server - SUSE:SLE-15:Update/xorg-x11-server - SUSE:SLE-15-SP1:Update/xorg-x11-server - SUSE:SLE-15-SP2:Update/xorg-x11-server - SUSE:SLE-15-SP4:Update/xorg-x11-server - SUSE:SLE-15-SP4:Update/xwayland For openSUSE: - openSUSE:Factory/xorg-x11-server - openSUSE:Factory/xwayland
I guess there won't be a CRD since the fix is already known/available via git?
(In reply to Stefan Dirsch from comment #2) > I guess there won't be a CRD since the fix is already known/available via > git? Yes, this is public
(In reply to Carlos López from comment #1) > Affected: > - SUSE:SLE-11-SP3:Update/xorg-x11-server > - SUSE:SLE-12-SP2:Update/xorg-x11-server > - SUSE:SLE-12-SP4:Update/xorg-x11-server > - SUSE:SLE-12-SP5:Update/xorg-x11-server > - SUSE:SLE-15:Update/xorg-x11-server > - SUSE:SLE-15-SP1:Update/xorg-x11-server > - SUSE:SLE-15-SP2:Update/xorg-x11-server > - SUSE:SLE-15-SP4:Update/xorg-x11-server > - SUSE:SLE-15-SP4:Update/xwayland > > For openSUSE: > - openSUSE:Factory/xorg-x11-server > - openSUSE:Factory/xwayland Packages updated and submitted now. Reassigning.
This is an autogenerated message for OBS integration: This bug (1204412) was mentioned in https://build.opensuse.org/request/show/1030009 Factory / xorg-x11-server https://build.opensuse.org/request/show/1030010 Factory / xwayland
SUSE-SU-2022:3840-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1204412,1204416 CVE References: CVE-2022-3550,CVE-2022-3551 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP3-BCL (src): xorg-x11-server-7.6_1.18.3-76.52.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): xorg-x11-server-7.6_1.18.3-76.52.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3841-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1204412,1204416 CVE References: CVE-2022-3550,CVE-2022-3551 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): xorg-x11-server-1.19.6-4.34.1 SUSE OpenStack Cloud 9 (src): xorg-x11-server-1.19.6-4.34.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): xorg-x11-server-1.19.6-4.34.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): xorg-x11-server-1.19.6-4.34.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3857-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1204412,1204416 CVE References: CVE-2022-3550,CVE-2022-3551 JIRA References: Sources used: openSUSE Leap 15.4 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 openSUSE Leap 15.3 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Manager Server 4.1 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Manager Retail Branch Server 4.1 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Manager Proxy 4.1 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise Workstation Extension 15-SP4 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise Workstation Extension 15-SP3 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise Server 15-SP2-BCL (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): xorg-x11-server-1.20.3-150200.22.5.58.1 SUSE Enterprise Storage 7 (src): xorg-x11-server-1.20.3-150200.22.5.58.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3856-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1204412,1204416 CVE References: CVE-2022-3550,CVE-2022-3551 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): xorg-x11-server-1.20.3-150100.14.5.28.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): xorg-x11-server-1.20.3-150100.14.5.28.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): xorg-x11-server-1.20.3-150100.14.5.28.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): xorg-x11-server-1.20.3-150100.14.5.28.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): xorg-x11-server-1.20.3-150100.14.5.28.1 SUSE Enterprise Storage 6 (src): xorg-x11-server-1.20.3-150100.14.5.28.1 SUSE CaaS Platform 4.0 (src): xorg-x11-server-1.20.3-150100.14.5.28.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3850-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1204412,1204416 CVE References: CVE-2022-3550,CVE-2022-3551 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15 (src): xorg-x11-server-1.19.6-150000.8.42.1 SUSE Linux Enterprise Server 15-LTSS (src): xorg-x11-server-1.19.6-150000.8.42.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): xorg-x11-server-1.19.6-150000.8.42.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): xorg-x11-server-1.19.6-150000.8.42.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3862-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1204412,1204416 CVE References: CVE-2022-3550,CVE-2022-3551 JIRA References: Sources used: openSUSE Leap 15.4 (src): xorg-x11-server-1.20.3-150400.38.8.1 SUSE Linux Enterprise Module for Development Tools 15-SP4 (src): xorg-x11-server-1.20.3-150400.38.8.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): xorg-x11-server-1.20.3-150400.38.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3863-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1204412,1204416 CVE References: CVE-2022-3550,CVE-2022-3551 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): xorg-x11-server-1.19.6-10.35.1 SUSE Linux Enterprise Server 12-SP5 (src): xorg-x11-server-1.19.6-10.35.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3941-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1204412,1204416 CVE References: CVE-2022-3550,CVE-2022-3551 JIRA References: Sources used: openSUSE Leap 15.4 (src): xwayland-21.1.4-150400.3.3.1 SUSE Linux Enterprise Workstation Extension 15-SP4 (src): xwayland-21.1.4-150400.3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.