CVE-2023-3138
published 2023-06-28CVE-2023-3138: A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.66%
74.0th percentile
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libx11 | < libx11 2:1.8.4-2+deb12u1 (bookworm) | libx11 2:1.8.4-2+deb12u1 (bookworm) |
| msrc | cbl2_libx11_1.6.12-6_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| x.org | libx11 | < 1.8.6 | 1.8.6 |
| x.org | libx11 | — | — |
| x.org | libx11 | >= 0 < 2:1.7.2-1+deb11u1 | 2:1.7.2-1+deb11u1 |
| x.org | libx11 | >= 0 < 2:1.8.4-2+deb12u1 | 2:1.8.4-2+deb12u1 |
| x.org | libx11 | >= 0 < 2:1.8.6-1 | 2:1.8.6-1 |
| x.org | libx11 | >= 0 < 2:1.8.6-1 | 2:1.8.6-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libx11 vulnerability
vendor_ubuntu·2023-06-20
CVE-2023-3138 libx11 vulnerability
Title: libx11 vulnerability
Summary: libx11 could be made to crash if it received specially crafted network
traffic.
USN-6168-1 fixed a vulnerability in libx11. This update provides
the corresponding update for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM,
and Ubuntu 18.04 ESM.
Original advisory details:
Gregory James Duck discovered that libx11 incorrectly handled certain
Request, Event, or Error IDs. If a user were tricked into connecting to a
malicious X Server, a remote attacker could possibly use this issue to
cause libx11 to crash, resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
BSD
OpenBSD 7.3 Errata 005: SECURITY FIX
bsd_advisories·2023-06-15·CVSS 7.5
CVE-2023-3138 [HIGH] OpenBSD 7.3 Errata 005: SECURITY FIX
OpenBSD 7.3 Errata 005: SECURITY FIX
005: SECURITY FIX: June 15, 2023
All architectures libX11 CVE-2023-3138 Missing checks in XQueryExtension() return values.
Ubuntu
libx11 vulnerability
vendor_ubuntu·2023-06-15
CVE-2023-3138 libx11 vulnerability
Title: libx11 vulnerability
Summary: libx11 could be made to crash if it received specially crafted network
traffic.
Gregory James Duck discovered that libx11 incorrectly handled certain
Request, Event, or Error IDs. If a user were tricked into connecting to a
malicious X Server, a remote attacker could possibly use this issue to
cause libx11 to crash, resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow
vendor_redhat·2023-06-15·CVSS 7.5
CVE-2023-3138 [HIGH] CWE-787 libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow
libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not w
BSD
OpenBSD 7.2 Errata 027: SECURITY FIX
bsd_advisories·2023-06-15·CVSS 7.5
CVE-2023-3138 [HIGH] OpenBSD 7.2 Errata 027: SECURITY FIX
OpenBSD 7.2 Errata 027: SECURITY FIX
027: SECURITY FIX: June 15, 2023
All architectures libX11 CVE-2023-3138 Missing checks in XQueryExtension() return values.
Microsoft
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request Event or Error IDs are within the b
vendor_msrc·2023-06-13·CVSS 7.5
CVE-2023-3138 [HIGH] CWE-787 A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request Event or Error IDs are within the b
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request Event or Error IDs are within the bounds of the arrays that those functions write to using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself possibly causing the client to crash with this memory corruption.
FAQ: Is Azur
Debian
CVE-2023-3138: libx11 - A vulnerability was found in libX11. The security flaw occurs because the functi...
vendor_debian·2023·CVSS 7.5
CVE-2023-3138 [HIGH] CVE-2023-3138: libx11 - A vulnerability was found in libX11. The security flaw occurs because the functi...
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.
Scope:
GHSA
GHSA-849h-8wj5-xmx8: A vulnerability was found in libX11
ghsa_unreviewed·2023-06-28
CVE-2023-3138 [HIGH] CWE-119 GHSA-849h-8wj5-xmx8: A vulnerability was found in libX11
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.
OSV
CVE-2023-3138: A vulnerability was found in libX11
osv·2023-06-28·CVSS 7.5
CVE-2023-3138 [HIGH] CVE-2023-3138: A vulnerability was found in libX11
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.
No detection rules found.
Nuclei
Payment Gateway for Telcell < 2.0.4 - Open Redirect
nuclei·CVSS 6.1
CVE-2023-6786 [MEDIUM] Payment Gateway for Telcell < 2.0.4 - Open Redirect
Payment Gateway for Telcell < 2.0.4 - Open Redirect
The plugin does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
Template:
id: CVE-2023-6786
info:
name: Payment Gateway for Telcell < 2.0.4 - Open Redirect
author: s4e-io
severity: medium
description: |
The plugin does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
impact: |
Unauthenticated attackers can exploit open redirect through the api_url parameter to redirect users to malicious websites for phishing attacks.
remediation: |
Fixed in 2.0.4
reference:
- https://wpscan.com/vulnerability/f3e64947-3138-4ec4-86c4-27b5d6a5c9c2/
- https://nvd.nist.gov/vuln/detail/CVE-2023-6786
classification:
cve-id: CVE-2023-6
arXiv
NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA
arxiv_fulltext·2025-06-08
NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA
: Scalable, Efficient, and Secure Memory Protection for Arm CCA
@IEEEauthorhalign
@IEEEauthorhalign
Shiqi Liu12,
Yongpeng Gao1,
Mingyang Zhang1,
Jie Wang1
The corresponding author.
1Huazhong University of Science and Technology
2George Mason University
[email protected], \sternen_hust, zoneshiyi, wangjie_s\@hust.edu.cn
1 The full name of the affiliation is Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology.
## Abstract
Arm Confidential Computing Architecture (CCA) currently isolates at the granularity of an entire Confidential Virtual Machine (CVM), leaving intra-VM bugs such as Heartbleed unmitigated. The state-of-the-art narrows this to the p
Bugzilla
CVE-2023-52580 kernel: net/core: kernel crash in ETH_P_1588 flow dissector
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52580 [MEDIUM] CVE-2023-52580 kernel: net/core: kernel crash in ETH_P_1588 flow dissector
CVE-2023-52580 kernel: net/core: kernel crash in ETH_P_1588 flow dissector
In the Linux kernel, the following vulnerability has been resolved:
net/core: Fix ETH_P_1588 flow dissector
The Linux kernel CVE team has assigned CVE-2023-52580 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030258-CVE-2023-52580-c37e@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3138 ht
https://access.redhat.com/security/cve/CVE-2023-3138https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/304a654a0d57bf0f00d8998185f0360332cfa36chttps://lists.x.org/archives/xorg-announce/2023-June/003406.htmlhttps://lists.x.org/archives/xorg-announce/2023-June/003407.htmlhttps://security.netapp.com/advisory/ntap-20231208-0008/https://access.redhat.com/security/cve/CVE-2023-3138https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/304a654a0d57bf0f00d8998185f0360332cfa36chttps://lists.x.org/archives/xorg-announce/2023-June/003406.htmlhttps://lists.x.org/archives/xorg-announce/2023-June/003407.htmlhttps://security.netapp.com/advisory/ntap-20231208-0008/
2023-06-28
Published