PT-2023-2371 · X.Org+10 · X.Org Server+11

Jan-Niklas Sohn

·

Published

2022-01-25

·

Updated

2024-06-15

·

CVE-2023-1393

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions X.Org Server versions prior to 21.1.8 xwayland versions prior to 23.1.1
Description A flaw was found in X.Org Server Overlay Window, where a Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window, the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later. This issue may be exploited to elevate privileges in systems where the X server runs with root privileges.
Recommendations For X.Org Server versions prior to 21.1.8, update to version 21.1.8 or later to resolve the issue. For xwayland versions prior to 23.1.1, update to version 23.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the compositor overlay window to minimize the risk of exploitation.

Fix

LPE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:1551
ALSA-2023:1592
ALSA-2023:6340
ALSA-2023:6341
ALSA-2023:6916
ALSA-2023:6917
ALT-PU-2022-1132
ALT-PU-2022-1459
ALT-PU-2023-1535
ALT-PU-2023-1578
ALT-PU-2023-7278
ALT-PU-2024-3261
AZL-25859
AZL-35358
AZL-44478
BDU:2023-02146
CESA-2023_1551
CESA-2023_6916
CESA-2023_6917
CVE-2023-1393
DLA-3372-1
DSA-5380-1
MGASA-2023-0131
OESA-2023-1239
OPENSUSE-SU-2024:12827-1
OPENSUSE-SU-2024:12834-1
RHSA-2023:1548
RHSA-2023:1549
RHSA-2023:1551
RHSA-2023:1592
RHSA-2023:1594
RHSA-2023:1598
RHSA-2023:1599
RHSA-2023:1600
RHSA-2023:6340
RHSA-2023:6341
RHSA-2023:6916
RHSA-2023:6917
RHSA-2023_1551
RHSA-2023_1592
RHSA-2023_1594
RHSA-2023_6340
RHSA-2023_6341
RHSA-2023_6916
RHSA-2023_6917
RHSA-2025:12751
RLSA-2023:1592
ROSA-SA-2023-2153
ROSA-SA-2023-2154
SUSE-SU-2023:1674-1
SUSE-SU-2023:1675-1
SUSE-SU-2023:1677-1
SUSE-SU-2023:1678-1
SUSE-SU-2023:1679-1
SUSE-SU-2023:1680-1
SUSE-SU-2023:1716-1
SUSE-SU-2023_1674-1
SUSE-SU-2023_1675-1
SUSE-SU-2023_1677-1
SUSE-SU-2023_1678-1
SUSE-SU-2023_1679-1
SUSE-SU-2023_1680-1
USN-5986-1
ZDI-23-359

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
X.Org Server
Xwayland