<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:55:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:2248 — Moderate: xorg-x11-server security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:2248</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: xorg-x11-server-Xdmx, AlmaLinux:9: xorg-x11-server-Xephyr, AlmaLinux:9: xorg-x11-server-Xnest, AlmaLinux:9: xorg-x11-server-Xorg, AlmaLinux:9: xorg-x11-server-Xvfb, AlmaLinux:9: xorg-x11-server-common, AlmaLinux:9: xorg-x11-server-devel, AlmaLinux:9: xorg-x11-server-source&lt;/p&gt;
&lt;p&gt;X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550)
* xorg-x11-server: XkbGetKbdByName use-after-free (CVE-2022-4283)
* xorg-x11-server: XTestSwapFakeInput stack overflow (CVE-2022-46340)
* xorg-x11-server: XIPassiveUngrab out-of-bounds access (CVE-2022-46341)
* xorg-x11-server: XvdiSelectVideoNotify use-after-free (CVE-2022-46342)
* xorg-x11-server: ScreenSaverSetAttributes use-after-free (CVE-2022-46343)
* xorg-x11-server: XIChangeProperty out-of-bounds access (CVE-2022-46344)
* xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494)
* xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: xorg-x11-server-Xdmx, AlmaLinux:9: xorg-x11-server-Xephyr, AlmaLinux:9: xorg-x11-server-Xnest, AlmaLinux:9: xorg-x11-server-Xorg, AlmaLinux:9: xorg-x11-server-Xvfb, AlmaLinux:9: xorg-x11-server-common, AlmaLinux:9: xorg-x11-server-devel, AlmaLinux:9: xorg-x11-server-source&lt;/p&gt;
&lt;p&gt;X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550)
* xorg-x11-server: XkbGetKbdByName use-after-free (CVE-2022-4283)
* xorg-x11-server: XTestSwapFakeInput stack overflow (CVE-2022-46340)
* xorg-x11-server: XIPassiveUngrab out-of-bounds access (CVE-2022-46341)
* xorg-x11-server: XvdiSelectVideoNotify use-after-free (CVE-2022-46342)
* xorg-x11-server: ScreenSaverSetAttributes use-after-free (CVE-2022-46343)
* xorg-x11-server: XIChangeProperty out-of-bounds access (CVE-2022-46344)
* xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494)
* xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:2248</guid>
    </item>
    <item>
      <title>bdu:2023-07837</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07837</link>
      <description>bdu:2023-07837</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07837</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-46342 — CVE-2022-46342 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-46342</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-46342</guid>
    </item>
    <item>
      <title>EUVD-2026-232425</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232425</link>
      <description>EUVD-2026-232425</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232425</guid>
    </item>
    <item>
      <title>fkie_cve-2022-46342</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46342</link>
      <description>&lt;p&gt;A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-46342</guid>
    </item>
    <item>
      <title>GHSA-5hp7-2mv5-p69r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5hp7-2mv5-p69r</link>
      <description>&lt;p&gt;A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5hp7-2mv5-p69r</guid>
    </item>
    <item>
      <title>gsd-2022-46342</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-46342</link>
      <description>gsd-2022-46342</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-46342</guid>
    </item>
    <item>
      <title>OESA-2022-2163 — xorg-x11-server security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2163</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xorg-x11-server, openEuler:20.03-LTS-SP3: xorg-x11-server, openEuler:22.03-LTS: xorg-x11-server&lt;/p&gt;
&lt;p&gt;Xephyr is an X server which has been implemented as an ordinary X application.  It runs in a window just like other X applications,but it is an X server itself in which you can run other software.  It is a very useful tool for developers who wish to test their applications without running them on their real X server.  Unlike Xnest, Xephyr renders to an X image rather than relaying the X protocol, and therefore supports the newer X extensions like Render and Composite.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se(CVE-2022-46342)&#13;
&#13;
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.(CVE-2022-46344)&#13;
&#13;
A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on systems where the X serve…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xorg-x11-server, openEuler:20.03-LTS-SP3: xorg-x11-server, openEuler:22.03-LTS: xorg-x11-server&lt;/p&gt;
&lt;p&gt;Xephyr is an X server which has been implemented as an ordinary X application.  It runs in a window just like other X applications,but it is an X server itself in which you can run other software.  It is a very useful tool for developers who wish to test their applications without running them on their real X server.  Unlike Xnest, Xephyr renders to an X image rather than relaying the X protocol, and therefore supports the newer X extensions like Render and Composite.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se(CVE-2022-46342)&#13;
&#13;
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.(CVE-2022-46344)&#13;
&#13;
A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on systems where the X serve…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2163</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12569-1 — xorg-x11-server-21.1.4-6.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12569-1</link>
      <description>&lt;p&gt;xorg-x11-server-21.1.4-6.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xorg-x11-server-21.1.4-6.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12569-1</guid>
    </item>
    <item>
      <title>RHSA-2025:12751 — Red Hat Security Advisory: tigervnc security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:12751</link>
      <description>&lt;p&gt;xorg-x11-server: XkbGetKbdByName use-after-free xorg-x11-server: XTestSwapFakeInput stack overflow xorg-x11-server: XIPassiveUngrab out-of-bounds access xorg-x11-server: XvdiSelectVideoNotify use-after-free xorg-x11-server: ScreenSaverSetAttributes use-after-free xorg-x11-server: XIChangeProperty out-of-bounds access xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access xorg-x11-server: tigervnc: heap-based buffer overflow privilege escalation vulnerability xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent xorg-x11-server: heap buffer overflow in DisableDevice xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice xorg-x11-server: Use-after-free in ProcRenderAddGlyphs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xorg-x11-server: XkbGetKbdByName use-after-free xorg-x11-server: XTestSwapFakeInput stack overflow xorg-x11-server: XIPassiveUngrab out-of-bounds access xorg-x11-server: XvdiSelectVideoNotify use-after-free xorg-x11-server: ScreenSaverSetAttributes use-after-free xorg-x11-server: XIChangeProperty out-of-bounds access xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access xorg-x11-server: tigervnc: heap-based buffer overflow privilege escalation vulnerability xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent xorg-x11-server: heap buffer overflow in DisableDevice xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice xorg-x11-server: Use-after-free in ProcRenderAddGlyphs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:12751</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:4481-1 — Security update for xorg-x11-server</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:4481-1</link>
      <description>&lt;p&gt;Security update for xorg-x11-server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xorg-x11-server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:4481-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-46342</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-46342</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server-hwe-16.04, Ubuntu:18.04:LTS: xorg-server, Ubuntu:18.04:LTS: xorg-server-hwe-18.04, Ubuntu:20.04:LTS: xorg-server, Ubuntu:22.04:LTS: xorg-server, Ubuntu:22.04:LTS: xwayland&lt;/p&gt;
&lt;p&gt;A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server-hwe-16.04, Ubuntu:18.04:LTS: xorg-server, Ubuntu:18.04:LTS: xorg-server-hwe-18.04, Ubuntu:20.04:LTS: xorg-server, Ubuntu:22.04:LTS: xorg-server, Ubuntu:22.04:LTS: xwayland&lt;/p&gt;
&lt;p&gt;A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-46342</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2312 — X.Org X11: Mehrere Schwachstellen ermöglichen Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2312</link>
      <description>&lt;p&gt;Ein lokaler oder entfernter, authentisierter Angreifer kann mehrere Schwachstellen in X.Org X11 ausnutzen, um seine Privilegien zu erhöhen und Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler oder entfernter, authentisierter Angreifer kann mehrere Schwachstellen in X.Org X11 ausnutzen, um seine Privilegien zu erhöhen und Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2312</guid>
    </item>
  </channel>
</rss>
