Skip to content
Commit ccdd431c authored by Peter Hutterer's avatar Peter Hutterer
Browse files

xkb: reset the radio_groups pointer to NULL after freeing it



Unlike other elements of the keymap, this pointer was freed but not
reset. On a subsequent XkbGetKbdByName request, the server may access
already freed memory.

CVE-2022-4283, ZDI-CAN-19530

This vulnerability was discovered by:
Jan-Niklas Sohn working with Trend Micro Zero Day Initiative

Signed-off-by: default avatarPeter Hutterer <peter.hutterer@who-t.net>
Acked-by: default avatarOlivier Fourdan <ofourdan@redhat.com>
parent 8f454b79
Loading
Loading
Loading
Pipeline #761893 passed with stages
in 3 minutes
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment