CVE-2022-49737: X.org X Server

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.

Affected products

  • X.org X Server: from 20.11, up to and including 21.1.16

Published 2025-03-16. Last modified 2026-06-17.