CVE-2023-0494

CWE-416Use After Free10 documents8 sources
Severity
7.8HIGH
EPSS
0.6%
top 30.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27

Description

A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDx.org/x_server< 21.1.7
Debianxorg-server< 2:1.20.11-1+deb11u5+3
CVEListV5xorg-x11-serverxorg-server 21.1.7
Debianxwayland< 2:22.1.8-1+2

Also affects: Fedora 36, 37, Enterprise Linux 8.0, 8.1, 9.0, 8.4, 8.6, 7.0, 8.2

Patches

🔴Vulnerability Details

3
OSV
CVE-2023-0494: A vulnerability was found in X2023-03-27
CVEList
CVE-2023-0494: A vulnerability was found in X2023-03-27
GHSA
GHSA-5v6x-2hpj-c37x: A vulnerability was found in X2023-03-27

📋Vendor Advisories

6
Ubuntu
X.Org X Server vulnerabilities2023-02-16
BSD
OpenBSD 7.2 Errata 019: SECURITY FIX2023-02-07
Ubuntu
X.Org X Server vulnerability2023-02-07
BSD
OpenBSD 7.1 Errata 023: SECURITY FIX2023-02-07
Red Hat
xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation2023-02-07
CVE-2023-0494 (HIGH CVSS 7.8) | A vulnerability was found in X.Org | cvebase.io