Back

MEDIUM

Xorg-x11-server: use-after-free bug in destroywindow

Published Oct 25, 2023

Description

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

Affected products

Remediation

Red Hat statement

The xorg-x11-server-Xwayland package as shipped by Red Hat Enterprise Linux 8 and 9 is not affected by this issue as Xwayland does not support multiple protocol screens and is not affected by this vulnerability.

Metrics

Weaknesses (1)

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 25, 2023
Updated Jun 23, 2026
Reserved Oct 4, 2023
CISA Vulnrichment
Updated Dec 1, 2023
NVD
Status Modified
Modified Jun 23, 2026
Red Hat
Severity Moderate
Public date Oct 25, 2023