CVE-2023-5380
published 2023-10-25CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with…
PriorityP419medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.71%
49.6th percentile
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xorg-server | < xorg-server 2:21.1.7-3+deb12u2 (bookworm) | xorg-server 2:21.1.7-3+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_xorg-x11-server_1.20.10-10_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| x.org | x_server | < 21.1.9 | 21.1.9 |
| x.org | xorg-server | >= 0 < 2:1.20.11-1+deb11u8 | 2:1.20.11-1+deb11u8 |
| x.org | xorg-server | >= 0 < 2:21.1.7-3+deb12u2 | 2:21.1.7-3+deb12u2 |
| x.org | xorg-server | >= 0 < 2:21.1.9-1 | 2:21.1.9-1 |
| x.org | xorg-server | >= 0 < 2:21.1.9-1 | 2:21.1.9-1 |
| x.org | xorg-server | >= 0 < 2:1.20.13-1ubuntu1~20.04.9 | 2:1.20.13-1ubuntu1~20.04.9 |
| x.org | xorg-server | >= 0 < 2:21.1.4-2ubuntu1.7~22.04.2 | 2:21.1.4-2ubuntu1.7~22.04.2 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.11+esm8 | 2:1.15.1-0ubuntu2.11+esm8 |
| x.org | xorg-server | >= 0 < 2:1.18.4-0ubuntu0.12+esm6 | 2:1.18.4-0ubuntu0.12+esm6 |
| x.org | xorg-server | >= 0 < 2:1.19.6-1ubuntu4.15+esm1 | 2:1.19.6-1ubuntu4.15+esm1 |
| x.org | xwayland | < 23.2.2 | 23.2.2 |
| x.org | xwayland | >= 0 < 2:22.1.1-1ubuntu0.7 | 2:22.1.1-1ubuntu0.7 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2023-10-31·CVSS 7.8
CVE-2023-5380 [HIGH] X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server, xwayland.
USN-6453-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS.
Original advisory details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
prepending values to certain properties. An attacker could possibly use
this issue to cause the X Server to crash, execute arbitrary code, or
escalate privileges. (CVE-2023-5367)
Sri discovered that the X.Org X Server incorrectly handled detroying
windows in certain legacy multi-screen setups. An attacker could possibly
use this issue to cause the X Server to crash, execute arbitrary code, or
escalate privileges. (CVE-2023-5
BSD
OpenBSD 7.3 Errata 018: SECURITY FIX
bsd_advisories·2023-10-25·CVSS 7.8
CVE-2023-5367 [HIGH] OpenBSD 7.3 Errata 018: SECURITY FIX
OpenBSD 7.3 Errata 018: SECURITY FIX
018: SECURITY FIX: October 25, 2023
All architectures Fix several input validation errors in the X server. CVE-2023-5367 CVE-2023-5380 CVE-2023-5574
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2023-10-25·CVSS 7.8
CVE-2023-5367 [HIGH] X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server, xwayland.
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
prepending values to certain properties. An attacker could possibly use
this issue to cause the X Server to crash, execute arbitrary code, or
escalate privileges. (CVE-2023-5367)
Sri discovered that the X.Org X Server incorrectly handled detroying
windows in certain legacy multi-screen setups. An attacker could possibly
use this issue to cause the X Server to crash, execute arbitrary code, or
escalate privileges. (CVE-2023-5380)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: Use-after-free bug in DestroyWindow
vendor_redhat·2023-10-25·CVSS 4.7
CVE-2023-5380 [MEDIUM] CWE-416 xorg-x11-server: Use-after-free bug in DestroyWindow
xorg-x11-server: Use-after-free bug in DestroyWindow
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed follo
BSD
OpenBSD 7.4 Errata 001: SECURITY FIX
bsd_advisories·2023-10-25·CVSS 7.8
CVE-2023-5367 [HIGH] OpenBSD 7.4 Errata 001: SECURITY FIX
OpenBSD 7.4 Errata 001: SECURITY FIX
001: SECURITY FIX: October 25, 2023
All architectures Fix several input validation errors in the X server. CVE-2023-5367 CVE-2023-5380 CVE-2023-5574
Microsoft
Xorg-x11-server: use-after-free bug in destroywindow
vendor_msrc·2023-10-10·CVSS 4.7
CVE-2023-5380 [MEDIUM] CWE-416 Xorg-x11-server: use-after-free bug in destroywindow
Xorg-x11-server: use-after-free bug in destroywindow
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.
Debian
CVE-2023-5380: xorg-server - A use-after-free flaw was found in the xorg-x11-server. An X server crash may oc...
vendor_debian·2023·CVSS 4.7
CVE-2023-5380 [MEDIUM] CVE-2023-5380: xorg-server - A use-after-free flaw was found in the xorg-x11-server. An X server crash may oc...
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u2)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u8)
forky: resolved (fixed in 2:21.1.9-1)
sid: resolved (fixed in 2:21.1.9-1)
trixie: resolved (fixed in 2:21.1.9-1)
OSV
xorg-server vulnerabilities
osv·2023-10-31·CVSS 7.8
CVE-2023-5367 [HIGH] xorg-server vulnerabilities
xorg-server vulnerabilities
USN-6453-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS.
Original advisory details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
prepending values to certain properties. An attacker could possibly use
this issue to cause the X Server to crash, execute arbitrary code, or
escalate privileges. (CVE-2023-5367)
Sri discovered that the X.Org X Server incorrectly handled detroying
windows in certain legacy multi-screen setups. An attacker could possibly
use this issue to cause the X Server to crash, execute arbitrary code, or
escalate privileges. (CVE-2023-5380)
OSV
xorg-server, xwayland vulnerabilities
osv·2023-10-25·CVSS 7.8
CVE-2023-5367 [HIGH] xorg-server, xwayland vulnerabilities
xorg-server, xwayland vulnerabilities
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
prepending values to certain properties. An attacker could possibly use
this issue to cause the X Server to crash, execute arbitrary code, or
escalate privileges. (CVE-2023-5367)
Sri discovered that the X.Org X Server incorrectly handled detroying
windows in certain legacy multi-screen setups. An attacker could possibly
use this issue to cause the X Server to crash, execute arbitrary code, or
escalate privileges. (CVE-2023-5380)
OSV
CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server
osv·2023-10-25·CVSS 4.7
CVE-2023-5380 [MEDIUM] CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
GHSA
GHSA-294c-hpxh-5qrx: A use-after-free flaw was found in the xorg-x11-server
ghsa_unreviewed·2023-10-25
CVE-2023-5380 [MEDIUM] CWE-416 GHSA-294c-hpxh-5qrx: A use-after-free flaw was found in the xorg-x11-server
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:7428https://access.redhat.com/errata/RHSA-2024:2169https://access.redhat.com/errata/RHSA-2024:2298https://access.redhat.com/errata/RHSA-2024:2995https://access.redhat.com/errata/RHSA-2024:3067https://access.redhat.com/security/cve/CVE-2023-5380https://bugzilla.redhat.com/show_bug.cgi?id=2244736https://lists.x.org/archives/xorg-announce/2023-October/003430.htmlhttps://access.redhat.com/errata/RHSA-2023:7428https://access.redhat.com/errata/RHSA-2024:2169https://access.redhat.com/errata/RHSA-2024:2298https://access.redhat.com/errata/RHSA-2024:2995https://access.redhat.com/errata/RHSA-2024:3067https://access.redhat.com/security/cve/CVE-2023-5380https://bugzilla.redhat.com/show_bug.cgi?id=2244736https://lists.debian.org/debian-lts-announce/2023/10/msg00036.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/2WS5E7H4A5J3U5YBCTMRPQVGWK5LVH7D/https://lists.fedoraproject.org/archives/list/[email protected]/message/3RK66CXMXO3PCPDU3GDY5FK4UYHUXQJT/https://lists.fedoraproject.org/archives/list/[email protected]/message/AKKIE626TZOOPD533EYN47J4RFNHZVOP/https://lists.fedoraproject.org/archives/list/[email protected]/message/HO2Q2NP6R62ZRQQG3XQ4AXUT7J2EKKKY/https://lists.fedoraproject.org/archives/list/[email protected]/message/SN6KV4XGQJRVAOSM5C3CWMVAXO53COIP/https://lists.fedoraproject.org/archives/list/[email protected]/message/TJXNI4BXURC2BKPNAHFJK3C5ZETB7PER/https://lists.x.org/archives/xorg-announce/2023-October/003430.htmlhttps://security.gentoo.org/glsa/202401-30https://security.netapp.com/advisory/ntap-20231130-0004/https://www.debian.org/security/2023/dsa-5534
2023-10-25
Published