CVE-2023-6816
Last modified
CVE-2023-6816 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. EPSS estimates a 2.11% chance of exploitation in the next 30 days.
Description
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X.Org | X Server | < 21.1.11 |
| X.Org | Xwayland | < 23.2.4 |
| Fedoraproject | Fedora | 39 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Debian | Debian Linux | 10.0 |
References
- https://access.redhat.com/errata/RHSA-2024:0320Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-6816Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257691Issue Tracking
- https://access.redhat.com/errata/RHSA-2024:0320Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-6816Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257691Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-6816?
How severe is CVE-2023-6816?
How do I fix CVE-2023-6816?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-6810The ClickCease Click Fraud Protection plugin for WordPress i…4.3
- CVE-2023-6811The Language Translate Widget for WordPress – ConveyThis plu…7.2
- CVE-2023-6812The WP Compress – Image Optimizer [All-In-One plugin for Wor…6.1
- CVE-2023-6813The Login by Auth0 plugin for WordPress is vulnerable to Ref…6.1
- CVE-2023-6814Insertion of Sensitive Information into Log File vulnerabili…5.6
- CVE-2023-6815Incorrect Privilege Assignment vulnerability in Mitsubishi E…6.5
- CVE-2023-6817A use-after-free vulnerability in the Linux kernel's netfilt…7.8
- CVE-2023-6818Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-6819Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-6820Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-6821The Error Log Viewer by BestWebSoft WordPress plugin before …6.5
- CVE-2023-6824The WP Customer Area WordPress plugin before 8.2.1 does not …6.5
Are you affected by CVE-2023-6816?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
