CVE-2022-27814
Rust vulnerability analysis and mitigation

Overview

SWHKD 1.1.5, a hotkey helper for Wayland, contains a security vulnerability that allows arbitrary file-existence tests via the -c option. The vulnerability was discovered during a security review of the RPM package integration submitted for openSUSE Tumbleweed and was assigned CVE-2022-27814 on March 24, 2022 (Openwall List).

Technical details

The vulnerability exists in the -c daemon command line parameter functionality. When exploited, it allows an attacker to perform arbitrary file existence tests on the system. For example, when executed with pkexec, the command can be used to test for the existence of files in privileged locations, providing information about the presence or absence of specific files (Openwall List).

Impact

The vulnerability allows unauthorized users to perform file existence tests on the system, potentially leading to information disclosure about the presence of sensitive files. This could be particularly problematic when combined with root privileges through pkexec, as it enables testing for the existence of privileged files (Openwall List).

Mitigation and workarounds

The issue was addressed in version 1.2.0 of SWHKD. The fix involves using the external cat program to read the configuration file. However, this is considered a workaround rather than a complete fix, as the root GID privilege is not properly dropped (GitHub Release, Openwall List).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-65807HIGH8.4
  • RustRust
  • rust-sd
NoNoDec 10, 2025
CVE-2025-66627HIGH7.8
  • RustRust
  • wasmi
NoYesDec 09, 2025
CVE-2025-67487MEDIUM5.5
  • RustRust
  • static-web-server
NoYesDec 09, 2025
CVE-2025-66622LOW1.3
  • RustRust
  • matrix-sdk-base
NoYesDec 09, 2025
RUSTSEC-2025-0135N/AN/A
  • RustRust
  • matrix-sdk-base
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management