CVE-2022-49737
CVSS 3.1 Score 7.7 of 10 (high)
Details
Published Mar 16, 2025
Updated: Mar 17, 2025
CWE ID 413
Summary
CVE-2022-49737 is a race condition vulnerability affecting X.Org X server versions 20.11 to 21.1.16. This issue occurs when a client application uses easystroke for mouse gestures and the main thread modifies data structures used by the input thread without acquiring a lock. Specifically, the function AttachDevice in dix/devices.c fails to acquire an input lock, leading to potential security vulnerabilities. This could allow an attacker to manipulate input data, leading to unintended actions or crashes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- X Window System 11
Affected Vendors
- X.Org