Name
CVE-2023-6816
Description
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2024:0320Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-6816Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2257691Issue Tracking
https://access.redhat.com/errata/RHSA-2024:0320Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-6816Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2257691Issue Tracking
Analysis#
Vulnerability Ratings#
9.8
CVSSv31
9.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
xserver-xorg (yocto:kirkstone)
#
Title
Author
Resolve
1
dix: allocate enough space for logical button maps
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2023-6816
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
dix: allocate enough space for logical button maps
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2023-6816