Bug 1204416 - (CVE-2022-3551) VUL-0: CVE-2022-3551: xorg-x11-server,xwayland: various leaks of the return value of GetComponentSpec()
(CVE-2022-3551)
VUL-0: CVE-2022-3551: xorg-x11-server,xwayland: various leaks of the return v...
Status: CONFIRMED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/345378/
CVSSv3.1:SUSE:CVE-2022-3551:5.5:(AV:L...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-10-18 08:39 UTC by Carlos López
Modified: 2022-11-10 17:25 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-10-18 08:39:42 UTC
CVE-2022-3551

A vulnerability, which was classified as problematic, has been found in X.org
Server. Affected by this issue is the function ProcXkbGetKbdByName of the file
xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a
patch to fix this issue. The identifier of this vulnerability is VDB-211052.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3551
https://www.cve.org/CVERecord?id=CVE-2022-3551
https://vuldb.com/?id.211052
https://cgit.freedesktop.org/xorg/xserver/commit/?id=18f91b950e22c2a342a4fbc55e9ddf7534a707d2
Comment 1 Carlos López 2022-10-18 08:41:43 UTC
Affected:
- SUSE:SLE-11-SP3:Update/xorg-x11-server
- SUSE:SLE-12-SP2:Update/xorg-x11-server
- SUSE:SLE-12-SP4:Update/xorg-x11-server
- SUSE:SLE-12-SP5:Update/xorg-x11-server
- SUSE:SLE-15:Update/xorg-x11-server
- SUSE:SLE-15-SP1:Update/xorg-x11-server
- SUSE:SLE-15-SP2:Update/xorg-x11-server
- SUSE:SLE-15-SP4:Update/xorg-x11-server
- SUSE:SLE-15-SP4:Update/xwayland

For openSUSE:
- openSUSE:Factory/xorg-x11-server
- openSUSE:Factory/xwayland
Comment 2 Stefan Dirsch 2022-10-19 13:55:54 UTC
(In reply to Carlos López from comment #1)
> Affected:
> - SUSE:SLE-11-SP3:Update/xorg-x11-server
> - SUSE:SLE-12-SP2:Update/xorg-x11-server
> - SUSE:SLE-12-SP4:Update/xorg-x11-server
> - SUSE:SLE-12-SP5:Update/xorg-x11-server
> - SUSE:SLE-15:Update/xorg-x11-server
> - SUSE:SLE-15-SP1:Update/xorg-x11-server
> - SUSE:SLE-15-SP2:Update/xorg-x11-server
> - SUSE:SLE-15-SP4:Update/xorg-x11-server
> - SUSE:SLE-15-SP4:Update/xwayland
> 
> For openSUSE:
> - openSUSE:Factory/xorg-x11-server
> - openSUSE:Factory/xwayland

Packages updated and submitted now. Reassigning.
Comment 3 OBSbugzilla Bot 2022-10-19 14:05:04 UTC
This is an autogenerated message for OBS integration:
This bug (1204416) was mentioned in
https://build.opensuse.org/request/show/1030009 Factory / xorg-x11-server
https://build.opensuse.org/request/show/1030010 Factory / xwayland
Comment 5 Swamp Workflow Management 2022-11-01 14:30:02 UTC
SUSE-SU-2022:3840-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204412,1204416
CVE References: CVE-2022-3550,CVE-2022-3551
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP3-BCL (src):    xorg-x11-server-7.6_1.18.3-76.52.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    xorg-x11-server-7.6_1.18.3-76.52.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2022-11-01 17:18:40 UTC
SUSE-SU-2022:3841-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204412,1204416
CVE References: CVE-2022-3550,CVE-2022-3551
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    xorg-x11-server-1.19.6-4.34.1
SUSE OpenStack Cloud 9 (src):    xorg-x11-server-1.19.6-4.34.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    xorg-x11-server-1.19.6-4.34.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    xorg-x11-server-1.19.6-4.34.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2022-11-02 17:22:41 UTC
SUSE-SU-2022:3857-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204412,1204416
CVE References: CVE-2022-3550,CVE-2022-3551
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
openSUSE Leap 15.3 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Manager Server 4.1 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Manager Retail Branch Server 4.1 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Manager Proxy 4.1 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise Workstation Extension 15-SP4 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise Workstation Extension 15-SP3 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise Module for Development Tools 15-SP3 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    xorg-x11-server-1.20.3-150200.22.5.58.1
SUSE Enterprise Storage 7 (src):    xorg-x11-server-1.20.3-150200.22.5.58.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2022-11-02 17:26:45 UTC
SUSE-SU-2022:3856-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204412,1204416
CVE References: CVE-2022-3550,CVE-2022-3551
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    xorg-x11-server-1.20.3-150100.14.5.28.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    xorg-x11-server-1.20.3-150100.14.5.28.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    xorg-x11-server-1.20.3-150100.14.5.28.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    xorg-x11-server-1.20.3-150100.14.5.28.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    xorg-x11-server-1.20.3-150100.14.5.28.1
SUSE Enterprise Storage 6 (src):    xorg-x11-server-1.20.3-150100.14.5.28.1
SUSE CaaS Platform 4.0 (src):    xorg-x11-server-1.20.3-150100.14.5.28.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2022-11-02 17:29:57 UTC
SUSE-SU-2022:3850-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204412,1204416
CVE References: CVE-2022-3550,CVE-2022-3551
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15 (src):    xorg-x11-server-1.19.6-150000.8.42.1
SUSE Linux Enterprise Server 15-LTSS (src):    xorg-x11-server-1.19.6-150000.8.42.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    xorg-x11-server-1.19.6-150000.8.42.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    xorg-x11-server-1.19.6-150000.8.42.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2022-11-03 14:20:04 UTC
SUSE-SU-2022:3862-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204412,1204416
CVE References: CVE-2022-3550,CVE-2022-3551
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    xorg-x11-server-1.20.3-150400.38.8.1
SUSE Linux Enterprise Module for Development Tools 15-SP4 (src):    xorg-x11-server-1.20.3-150400.38.8.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    xorg-x11-server-1.20.3-150400.38.8.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2022-11-03 14:20:57 UTC
SUSE-SU-2022:3863-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204412,1204416
CVE References: CVE-2022-3550,CVE-2022-3551
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    xorg-x11-server-1.19.6-10.35.1
SUSE Linux Enterprise Server 12-SP5 (src):    xorg-x11-server-1.19.6-10.35.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2022-11-10 17:25:20 UTC
SUSE-SU-2022:3941-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204412,1204416
CVE References: CVE-2022-3550,CVE-2022-3551
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    xwayland-21.1.4-150400.3.3.1
SUSE Linux Enterprise Workstation Extension 15-SP4 (src):    xwayland-21.1.4-150400.3.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.