cbcvebase.
CVE-2023-6377
published 2023-12-13

CVE-2023-6377: A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianxorg-server< xorg-server 2:21.1.7-3+deb12u4 (bookworm)xorg-server 2:21.1.7-3+deb12u4 (bookworm)
debianxwayland< xorg-server 2:21.1.7-3+deb12u4 (bookworm)xorg-server 2:21.1.7-3+deb12u4 (bookworm)
msrccbl2_xorg-x11-server_1.20.10-5_on_cbl_mariner_2.0
redhatenterprise_linux_eus
x.orgx_server< 21.1.1021.1.10
x.orgxorg-server>= 0 < 2:1.20.11-1+deb11u102:1.20.11-1+deb11u10
x.orgxorg-server>= 0 < 2:21.1.7-3+deb12u42:21.1.7-3+deb12u4
x.orgxorg-server>= 0 < 2:21.1.10-12:21.1.10-1
x.orgxorg-server>= 0 < 2:21.1.10-12:21.1.10-1
x.orgxorg-server>= 0 < 2:1.20.13-1ubuntu1~20.04.122:1.20.13-1ubuntu1~20.04.12
x.orgxorg-server>= 0 < 2:21.1.4-2ubuntu1.7~22.04.52:21.1.4-2ubuntu1.7~22.04.5
x.orgxorg-server>= 0 < 2:1.18.4-0ubuntu0.12+esm82:1.18.4-0ubuntu0.12+esm8
x.orgxorg-server>= 0 < 2:1.19.6-1ubuntu4.15+esm32:1.19.6-1ubuntu4.15+esm3
x.orgxwayland< 23.2.323.2.3
x.orgxwayland>= 0 < 2:23.2.3-12:23.2.3-1
x.orgxwayland>= 0 < 2:23.2.3-12:23.2.3-1
x.orgxwayland>= 0 < 2:22.1.1-1ubuntu0.92:22.1.1-1ubuntu0.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH