XWayland Hit By Its First Security Advisory: Missing Authentication

Written by Michael Larabel in Linux Security on 10 June 2015 at 11:32 AM EDT. 5 Comments
LINUX SECURITY
(X)Wayland has its first security notice today thanks to a discovery made by a Red Hat developer.

It turns out that the XWayland server currently starts up in a non-authenticating mode, thus any client with access to the server UNIX socket could connect to the server and use it. However, there's no Wayland compositors out there known to start XWayland with open TCP access, so at least remote exploits aren't expected. But this does mean that locally, untrusted users could capture input meant from other X11 clients, etc.

Fortunately, it's not a design flaw within Wayland but rather an issue with the XWayland DDX in the X.Org Server that's used by Weston 1.5+ and GNOME Shell/Mutter.

This CVE-2015-3164 issue is fixed in the latest X.Org Server Git code to be found in future X.Org Server 1.17 point releases and the 1.18 major release. More details in the advisory mailed out a few minutes ago by Daniel Stone.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week