Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with a no-op modmask expression.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libxkbcommon | Xkbcommon | * | 0.8.1 (including) |
Xkbcommon | Xkbcommon | * | 0.8.1 (including) |
Red Hat Enterprise Linux 7 | RedHat | gdm-1:3.28.2-16.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | libX11-0:1.6.7-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | libxkbcommon-0:0.7.1-3.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | mesa-libGLw-0:8.0.0-5.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | xorg-x11-drv-ati-0:19.0.1-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | xorg-x11-drv-vesa-0:2.4.0-3.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | xorg-x11-drv-wacom-0:0.36.1-3.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | xorg-x11-server-0:1.20.4-7.el7 | * |
Libxkbcommon | Ubuntu | bionic | * |
Libxkbcommon | Ubuntu | trusty | * |
Libxkbcommon | Ubuntu | upstream | * |
Libxkbcommon | Ubuntu | xenial | * |