CVE-2022-49737
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
16/03/2025
Última modificación:
16/03/2025
Descripción
*** Pendiente de traducción *** In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.
Impacto
Puntuación base 3.x
7.70
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1%3Bbug%3D1081338%3Bfilename%3Ddix-Hold-input-lock-for-AttachDevice.patch%3Bmsg%3D5
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1081338
- https://gitlab.freedesktop.org/xorg/xserver/-/commit/dc7cb45482cea6ccec22d117ca0b489500b4d0a0
- https://gitlab.freedesktop.org/xorg/xserver/-/issues/1260