PT-2022-6818 · Xterm+9 · Xterm+9

David Leadbeater

·

Published

2022-10-23

·

Updated

2026-04-08

·

CVE-2022-45063

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xterm versions prior to 375
Description The issue is related to the lack of input validation in the xterm terminal emulator, which can be exploited by a remote attacker to gain access to confidential data, compromise its integrity, and cause a denial of service. The vulnerability can be exploited via font operations, for example, because an OSC 50 response may contain Ctrl-g, leading to command execution within the vi line-editing mode of Zsh. It is noted that font operations are not allowed in the xterm default configurations of some Linux distributions.
Recommendations For xterm versions prior to 375, update to version 375 or later to resolve the issue. As a temporary workaround, consider disabling font operations until a patch is available. Restrict access to the vi line-editing mode of Zsh to minimize the risk of exploitation. Avoid using the Ctrl-g character in OSC 50 responses until the issue is resolved.

Exploit

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

ALSA-2025:7427
ALT-PU-2022-3062
ALT-PU-2022-3205
ALT-PU-2022-3213
AZL-11429
BDU:2023-04813
CVE-2022-45063
INFSA-2025_7427
MGASA-2022-0441
OESA-2024-2236
OESA-2024-2237
OESA-2024-2238
OESA-2024-2239
OPENSUSE-SU-2023_0221-1
OPENSUSE-SU-2024:12505-1
RHSA-2025:7427
RHSA-2025_7427
SUSE-SU-2023:0173-1
SUSE-SU-2023:0221-1
SUSE-SU-2023:0582-1
SUSE-SU-2023_0173-1
SUSE-SU-2023_0221-1
SUSE-SU-2023_0582-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Debian
Red Hat
Red Os
Rocky Linux
Suse
Zsh
Xterm