CVE-2023-6816
Last modified
CVE-2023-6816 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. EPSS estimates a 2.11% chance of exploitation in the next 30 days.
Description
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X.Org | X Server | < 21.1.11 |
| X.Org | Xwayland | < 23.2.4 |
| Fedoraproject | Fedora | 39 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Debian | Debian Linux | 10.0 |
References
- https://access.redhat.com/errata/RHSA-2024:0320Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-6816Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257691Issue Tracking
- https://access.redhat.com/errata/RHSA-2024:0320Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-6816Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257691Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-6816?
How severe is CVE-2023-6816?
How do I fix CVE-2023-6816?
Are you affected by CVE-2023-6816?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
