cbcvebase.
CVE-2023-5367
published 2023-10-25

CVE-2023-5367: A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.62%
45.7th percentile
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianxorg-server< xorg-server 2:21.1.7-3+deb12u2 (bookworm)xorg-server 2:21.1.7-3+deb12u2 (bookworm)
debianxwayland< xorg-server 2:21.1.7-3+deb12u2 (bookworm)xorg-server 2:21.1.7-3+deb12u2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_xorg-x11-server_1.20.10-10_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_power_big_endian
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_scientific_computing
redhatenterprise_linux_server
redhatenterprise_linux_workstation
x.orgx_server< 21.1.921.1.9
x.orgxorg-server>= 0 < 2:1.20.11-1+deb11u82:1.20.11-1+deb11u8
x.orgxorg-server>= 0 < 2:21.1.7-3+deb12u22:21.1.7-3+deb12u2
x.orgxorg-server>= 0 < 2:21.1.9-12:21.1.9-1
x.orgxorg-server>= 0 < 2:21.1.9-12:21.1.9-1
x.orgxorg-server>= 0 < 2:1.20.13-1ubuntu1~20.04.92:1.20.13-1ubuntu1~20.04.9
x.orgxorg-server>= 0 < 2:21.1.4-2ubuntu1.7~22.04.22:21.1.4-2ubuntu1.7~22.04.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.