PT-2023-8328 · Unknown+10 · Xorg-X11-Server+10
Jan-Niklas Sohn
+1
·
Published
2023-12-12
·
Updated
2026-02-25
·
CVE-2023-6377
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xorg-x11-server (affected versions not specified)
Description
A flaw was found in xorg-server, related to the handling of XKB button actions, which can result in out-of-bounds memory reads and writes when querying or changing these actions, such as moving from a touchpad to a mouse. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
LPE
Memory Corruption
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Suse
Ubuntu
Xorg-X11-Server