OESA-2022-1920 (CVE-2021-3782)

Vulnerability from osv_openeuler – Published: 2022-09-16 11:05 – Updated: 2026-08-06 11:05 – Source website
VLAI
Summary
wayland security update
Details

Wayland is a protocol for a compositor to talk to its clients as well as a C library implementation of that protocol. The compositor can be a standalone display server running on Linux kernel modesetting and evdev input devices, an X application, or a wayland client itself. The clients can be traditional applications, X servers (rootless or fullscreen) or other display servers. Part of the Wayland project is also the Weston reference implementation of a Wayland compositor. Weston can run as an X client or under Linux KMS and ships with a few demo clients. The Weston compositor is a minimal and fast compositor and is suitable for many embedded and mobile use cases.

Security Fix(es):

An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count is maintained as an int; on LP64 systems this can cause the reference count to overflow if the client creates a large number of wl_shm buffer objects, or if it can coerce the server to create a large number of external references to the buffer storage. With the reference count overflowing, a use-after-free can be constructed on the wl_shm_pool tracking structure, where values may be incremented or decremented; it may also be possible to construct a limited oracle to leak 4 bytes of server-side memory to the attacking client at a time.(CVE-2021-3782)


{
  "affected": [
    {
      "ecosystem_specific": {
        "aarch64": [
          "wayland-debuginfo-1.17.0-3.oe1.aarch64.rpm",
          "wayland-debugsource-1.17.0-3.oe1.aarch64.rpm",
          "wayland-devel-1.17.0-3.oe1.aarch64.rpm",
          "wayland-1.17.0-3.oe1.aarch64.rpm"
        ],
        "noarch": [
          "wayland-help-1.17.0-3.oe1.noarch.rpm"
        ],
        "src": [
          "wayland-1.17.0-3.oe1.src.rpm"
        ],
        "x86_64": [
          "wayland-debuginfo-1.17.0-3.oe1.x86_64.rpm",
          "wayland-devel-1.17.0-3.oe1.x86_64.rpm",
          "wayland-debugsource-1.17.0-3.oe1.x86_64.rpm",
          "wayland-1.17.0-3.oe1.x86_64.rpm"
        ]
      },
      "package": {
        "ecosystem": "openEuler:20.03-LTS-SP1",
        "name": "wayland",
        "purl": "pkg:rpm/openEuler/wayland\u0026distro=openEuler-20.03-LTS-SP1"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.17.0-3.oe1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "aarch64": [
          "wayland-1.17.0-3.oe1.aarch64.rpm",
          "wayland-devel-1.17.0-3.oe1.aarch64.rpm",
          "wayland-debugsource-1.17.0-3.oe1.aarch64.rpm",
          "wayland-debuginfo-1.17.0-3.oe1.aarch64.rpm"
        ],
        "noarch": [
          "wayland-help-1.17.0-3.oe1.noarch.rpm"
        ],
        "src": [
          "wayland-1.17.0-3.oe1.src.rpm"
        ],
        "x86_64": [
          "wayland-devel-1.17.0-3.oe1.x86_64.rpm",
          "wayland-1.17.0-3.oe1.x86_64.rpm",
          "wayland-debugsource-1.17.0-3.oe1.x86_64.rpm",
          "wayland-debuginfo-1.17.0-3.oe1.x86_64.rpm"
        ]
      },
      "package": {
        "ecosystem": "openEuler:20.03-LTS-SP3",
        "name": "wayland",
        "purl": "pkg:rpm/openEuler/wayland\u0026distro=openEuler-20.03-LTS-SP3"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.17.0-3.oe1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "aarch64": [
          "wayland-debuginfo-1.19.91-4.oe2203.aarch64.rpm",
          "wayland-1.19.91-4.oe2203.aarch64.rpm",
          "wayland-devel-1.19.91-4.oe2203.aarch64.rpm",
          "wayland-debugsource-1.19.91-4.oe2203.aarch64.rpm"
        ],
        "noarch": [
          "wayland-help-1.19.91-4.oe2203.noarch.rpm"
        ],
        "src": [
          "wayland-1.19.91-4.oe2203.src.rpm"
        ],
        "x86_64": [
          "wayland-devel-1.19.91-4.oe2203.x86_64.rpm",
          "wayland-1.19.91-4.oe2203.x86_64.rpm",
          "wayland-debuginfo-1.19.91-4.oe2203.x86_64.rpm",
          "wayland-debugsource-1.19.91-4.oe2203.x86_64.rpm"
        ]
      },
      "package": {
        "ecosystem": "openEuler:22.03-LTS",
        "name": "wayland",
        "purl": "pkg:rpm/openEuler/wayland\u0026distro=openEuler-22.03-LTS"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.19.91-4.oe2203"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "severity": "Medium"
  },
  "details": "Wayland is a protocol for a compositor to talk to its clients as well as a C library implementation of that protocol. The compositor can be a standalone display server running on Linux kernel modesetting and evdev input devices, an X application, or a wayland client itself. The clients can be traditional applications, X servers (rootless or fullscreen) or other display servers. Part of the Wayland project is also the Weston reference implementation of a Wayland compositor. Weston can run as an X client or under Linux KMS and ships with a few demo clients. The Weston compositor is a minimal and fast compositor and is suitable for many embedded and mobile use cases.\r\n\r\nSecurity Fix(es):\r\n\r\nAn internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count is maintained as an int; on LP64 systems this can cause the reference count to overflow if the client creates a large number of wl_shm buffer objects, or if it can coerce the server to create a large number of external references to the buffer storage. With the reference count overflowing, a use-after-free can be constructed on the wl_shm_pool tracking structure, where values may be incremented or decremented; it may also be possible to construct a limited oracle to leak 4 bytes of server-side memory to the attacking client at a time.(CVE-2021-3782)",
  "id": "OESA-2022-1920",
  "modified": "2026-08-06T11:05:14Z",
  "published": "2022-09-16T11:05:14Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1920"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3782"
    }
  ],
  "schema_version": "1.7.2",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "wayland security update",
  "upstream": [
    "CVE-2021-3782"
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…