Name
CVE-2023-5367
Description
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2023:6802Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:6808Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7373Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7388Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7405Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7428Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7436Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7526Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7533Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0010Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0128Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-5367Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2243091Issue Tracking
https://access.redhat.com/errata/RHSA-2023:6802Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:6808Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7373Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7388Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7405Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7428Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7436Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7526Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7533Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0010Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0128Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-5367Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2243091Issue Tracking
Analysis#
Vulnerability Ratings#
7.8
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
xserver-xorg (yocto:kirkstone)
#
Title
Author
Resolve
1
Xi/randr: fix handling of PropModeAppend/Prepend
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2023-5367
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
Xi/randr: fix handling of PropModeAppend/Prepend
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2023-5367