Back

HIGH

Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty

Published Oct 25, 2023

Description

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore, Red Hat Enterprise Linux 8 and 9 have been rated with a moderate severity.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 25, 2023
Updated Jun 23, 2026
Reserved Oct 3, 2023
CISA Vulnrichment
Updated Dec 1, 2023
NVD
Status Modified
Modified Jun 23, 2026
Red Hat
Severity Important
Public date Oct 25, 2023