Name
CVE-2023-6377
Description
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2023:7886Vendor Advisory
https://access.redhat.com/security/cve/CVE-2023-6377Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2253291Issue Tracking
https://access.redhat.com/errata/RHSA-2023:7886Vendor Advisory
https://access.redhat.com/security/cve/CVE-2023-6377Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2253291Issue Tracking
Analysis#
Vulnerability Ratings#
7.8
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
xserver-xorg (yocto:kirkstone)
#
Title
Author
Resolve
1
Xi: allocate enough XkbActions for our buttons
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2023-6377
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
Xi: allocate enough XkbActions for our buttons
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2023-6377