CVE-2022-49737

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Mar 16, 2025
Updated: Mar 17, 2025
CWE ID 413

Summary

CVE-2022-49737 is a race condition vulnerability affecting X.Org X server versions 20.11 to 21.1.16. This issue occurs when a client application uses easystroke for mouse gestures and the main thread modifies data structures used by the input thread without acquiring a lock. Specifically, the function AttachDevice in dix/devices.c fails to acquire an input lock, leading to potential security vulnerabilities. This could allow an attacker to manipulate input data, leading to unintended actions or crashes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share