PT-2023-1496 · X.Org+10 · X.Org Server+10

Jan-Niklas Sohn

·

Published

2023-02-07

·

Updated

2025-02-24

·

CVE-2023-0494

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions X.Org Server versions prior to 21.1.7
Description A vulnerability was found in X.Org due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Recommendations For X.Org Server versions prior to 21.1.7, update to version 21.1.7 to resolve the issue. As a temporary workaround, consider restricting access to the ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() functions until a patch is available.

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2023:0622
ALSA-2023:0662
ALSA-2023:2248
ALSA-2023:2249
ALSA-2023:2805
ALSA-2023:2806
ALT-PU-2023-1188
ALT-PU-2023-1254
ALT-PU-2023-7278
ALT-PU-2024-3261
BDU:2023-00910
CESA-2023_0662
CESA-2023_0675
CESA-2023_2805
CESA-2023_2806
CVE-2023-0494
DLA-3310-1
DSA-5342-1
MGASA-2023-0118
OESA-2023-1127
OPENSUSE-SU-2023_0285-1
OPENSUSE-SU-2023_0288-1
OPENSUSE-SU-2023_0289-1
OPENSUSE-SU-2024:12664-1
OPENSUSE-SU-2024:12665-1
RHSA-2023:0622
RHSA-2023:0623
RHSA-2023:0662
RHSA-2023:0663
RHSA-2023:0664
RHSA-2023:0665
RHSA-2023:0671
RHSA-2023:0675
RHSA-2023:2248
RHSA-2023:2249
RHSA-2023:2805
RHSA-2023:2806
RHSA-2023_0622
RHSA-2023_0662
RHSA-2023_0675
RHSA-2023_2248
RHSA-2023_2249
RHSA-2023_2805
RHSA-2023_2806
RHSA-2025:12751
RLSA-2023:0622
RLSA-2023:0662
ROSA-SA-2023-2125
ROSA-SA-2023-2126
SUSE-SU-2023:0282-1
SUSE-SU-2023:0284-1
SUSE-SU-2023:0285-1
SUSE-SU-2023:0286-1
SUSE-SU-2023:0287-1
SUSE-SU-2023:0288-1
SUSE-SU-2023:0289-1
SUSE-SU-2023_0282-1
SUSE-SU-2023_0284-1
SUSE-SU-2023_0285-1
SUSE-SU-2023_0286-1
SUSE-SU-2023_0287-1
SUSE-SU-2023_0288-1
USN-5778-2
USN-5846-1
ZDI-23-098

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
X.Org Server