Xorg-x11-server: use-after-free bug in destroywindow
Published Oct 25, 2023
4.7
MEDIUMCVSS 3.1
EPSS 0.71%
Description
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected |
|
Configuration 2
- 7.0
- 8.0
- 9.0
Configuration 3
- 37
- 38
- 39
Configuration 4
- 11.0
- 12.0
No data.
Red Hat Enterprise Linux 7
tigervnc-0:1.8.0-26.el7_9
Fixed · RHSA-2023:7428
Red Hat Enterprise Linux 8
tigervnc-0:1.13.1-8.el8
Fixed · RHSA-2024:3067
Red Hat Enterprise Linux 8
xorg-x11-server-0:1.20.11-22.el8
Fixed · RHSA-2024:2995
Red Hat Enterprise Linux 9
tigervnc-0:1.13.1-8.el9
Fixed · RHSA-2024:2298
Red Hat Enterprise Linux 9
xorg-x11-server-0:1.20.11-24.el9
Fixed · RHSA-2024:2169
Red Hat Enterprise Linux 6
tigervnc
Out of support scope
Red Hat Enterprise Linux 6
xorg-x11-server
Out of support scope
Red Hat Enterprise Linux 7
xorg-x11-server
Will not fix
Red Hat Enterprise Linux 8
xorg-x11-server-Xwayland
Not affected
Red Hat Enterprise Linux 9
xorg-x11-server-Xwayland
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | tigervnc-0:1.8.0-26.el7_9 | Fixed | RHSA-2023:7428 |
| Red Hat Enterprise Linux 8 | tigervnc-0:1.13.1-8.el8 | Fixed | RHSA-2024:3067 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-0:1.20.11-22.el8 | Fixed | RHSA-2024:2995 |
| Red Hat Enterprise Linux 9 | tigervnc-0:1.13.1-8.el9 | Fixed | RHSA-2024:2298 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-0:1.20.11-24.el9 | Fixed | RHSA-2024:2169 |
| Red Hat Enterprise Linux 6 | tigervnc | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | xorg-x11-server | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Not affected | n/a |
| Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The xorg-x11-server-Xwayland package as shipped by Red Hat Enterprise Linux 8 and 9 is not affected by this issue as Xwayland does not support multiple protocol screens and is not affected by this vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Dec 1, 2023 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2023-2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.71% (0.00715) | 52.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.71% (0.00715) | 48.72th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00056) | 14.58th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 18.07th | v3 (v2023.03.01) |
| May 31, 2024 | 0.04% (0.00044) | 9.85th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.04% (0.00044) | 7.85th | v3 (v2023.03.01) |
| Jan 1, 2024 | 0.04% (0.00045) | 12.70th | v3 (v2023.03.01) |
| Nov 3, 2023 | 0.04% (0.00042) | 5.71th | v3 (v2023.03.01) |
| Oct 26, 2023 | 0.05% (0.00053) | 19.40th | v3 (v2023.03.01) |
References (20)
- https://access.redhat.com/errata/RHSA-2023:7428 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:2169 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2298 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2995 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:3067 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5380 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2244736 issue-trackingx_refsource_REDHATIssue Tracking
- https://lists.debian.org/debian-lts-announce/2023/10/msg00036.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WS5E7H4A5J3U5YBCTMRPQVGWK5LVH7D/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3RK66CXMXO3PCPDU3GDY5FK4UYHUXQJT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKKIE626TZOOPD533EYN47J4RFNHZVOP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HO2Q2NP6R62ZRQQG3XQ4AXUT7J2EKKKY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SN6KV4XGQJRVAOSM5C3CWMVAXO53COIP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJXNI4BXURC2BKPNAHFJK3C5ZETB7PER/
- https://lists.x.org/archives/xorg-announce/2023-October/003430.html PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-5380
- https://security.gentoo.org/glsa/202401-30
- https://security.netapp.com/advisory/ntap-20231130-0004/
- https://www.cve.org/CVERecord?id=CVE-2023-5380
- https://www.debian.org/security/2023/dsa-5534
Change history (0)
No recorded changes yet.