Back

HIGH

Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty

Published Dec 13, 2023

Description

A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore, Red Hat Enterprise Linux 8 and 9 have been rated with a moderate severity.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 13, 2023
Updated Jun 23, 2026
Reserved Dec 4, 2023
CISA Vulnrichment
Updated Dec 19, 2023
NVD
Status Modified
Modified Jun 23, 2026
Red Hat
Severity Important
Public date Dec 13, 2023
ENISA EUVD
Assigner redhat
Published Dec 13, 2023
Updated Jun 23, 2026
Exploited since n/a
EUVD-2023-58711