CVE-2023-5380

CWE-416Use After Free13 documents9 sources
Severity
4.7MEDIUM
EPSS
0.1%
top 76.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateOct 31

Description

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages3 packages

Debianxorg-server< 2:1.20.11-1+deb11u8+3
NVDx.org/x_server< 21.1.9
NVDx.org/xwayland< 23.2.2

Also affects: Debian Linux 11.0, 12.0, Fedora 37, 38, 39, Enterprise Linux 7.0, 8.0, 9.0

Patches

🔴Vulnerability Details

5
OSV
xorg-server vulnerabilities2023-10-31
CVEList
Xorg-x11-server: use-after-free bug in destroywindow2023-10-25
OSV
CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server2023-10-25
GHSA
GHSA-294c-hpxh-5qrx: A use-after-free flaw was found in the xorg-x11-server2023-10-25
OSV
xorg-server, xwayland vulnerabilities2023-10-25

📋Vendor Advisories

7
Ubuntu
X.Org X Server vulnerabilities2023-10-31
BSD
OpenBSD 7.3 Errata 018: SECURITY FIX2023-10-25
Ubuntu
X.Org X Server vulnerabilities2023-10-25
Red Hat
xorg-x11-server: Use-after-free bug in DestroyWindow2023-10-25
BSD
OpenBSD 7.4 Errata 001: SECURITY FIX2023-10-25