Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty
Published Dec 13, 2023
7.6
HIGHCVSS 3.1
EPSS 1.62%
Description
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
Affected products
No data.
Configuration 1
Running on/with
- 6.0
- 7.0
- 8.0
- 9.0
Configuration 2
Running on/with
- 8.0
- 9.0
Configuration 3
- 9.2
Configuration 4
- 10.0
- 11.0
- 12.0
Configuration 5
Running on/with
- 6.0
- 7.0
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
tigervnc-0:1.1.0-25.el6_10.13
Fixed · RHSA-2025:12751
Red Hat Enterprise Linux 7
tigervnc-0:1.8.0-28.el7_9
Fixed · RHSA-2024:0006
Red Hat Enterprise Linux 7
xorg-x11-server-0:1.20.4-25.el7_9
Fixed · RHSA-2024:0009
Red Hat Enterprise Linux 8
tigervnc-0:1.13.1-2.el8_9.4
Fixed · RHSA-2024:0018
Red Hat Enterprise Linux 8
xorg-x11-server-0:1.20.11-22.el8
Fixed · RHSA-2024:2995
Red Hat Enterprise Linux 8
xorg-x11-server-Xwayland-0:21.1.3-15.el8
Fixed · RHSA-2024:2996
Red Hat Enterprise Linux 8.2 Advanced Update Support
tigervnc-0:1.9.0-15.el8_2.6
Fixed · RHSA-2024:0017
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
tigervnc-0:1.9.0-15.el8_2.6
Fixed · RHSA-2024:0017
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
tigervnc-0:1.9.0-15.el8_2.6
Fixed · RHSA-2024:0017
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
tigervnc-0:1.11.0-8.el8_4.5
Fixed · RHSA-2024:0016
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
tigervnc-0:1.11.0-8.el8_4.5
Fixed · RHSA-2024:0016
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
tigervnc-0:1.11.0-8.el8_4.5
Fixed · RHSA-2024:0016
Red Hat Enterprise Linux 8.6 Extended Update Support
tigervnc-0:1.12.0-6.el8_6.6
Fixed · RHSA-2024:0015
Red Hat Enterprise Linux 8.8 Extended Update Support
tigervnc-0:1.12.0-15.el8_8.4
Fixed · RHSA-2024:0014
Red Hat Enterprise Linux 9
tigervnc-0:1.13.1-3.el9_3.3
Fixed · RHSA-2024:0010
Red Hat Enterprise Linux 9
xorg-x11-server-0:1.20.11-24.el9
Fixed · RHSA-2024:2169
Red Hat Enterprise Linux 9
xorg-x11-server-Xwayland-0:22.1.9-5.el9
Fixed · RHSA-2024:2170
Red Hat Enterprise Linux 9.0 Extended Update Support
tigervnc-0:1.11.0-22.el9_0.5
Fixed · RHSA-2024:0020
Red Hat Enterprise Linux 9.2 Extended Update Support
tigervnc-0:1.12.0-14.el9_2.2
Fixed · RHSA-2023:7886
Red Hat Enterprise Linux 6
xorg-x11-server
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | tigervnc-0:1.1.0-25.el6_10.13 | Fixed | RHSA-2025:12751 |
| Red Hat Enterprise Linux 7 | tigervnc-0:1.8.0-28.el7_9 | Fixed | RHSA-2024:0006 |
| Red Hat Enterprise Linux 7 | xorg-x11-server-0:1.20.4-25.el7_9 | Fixed | RHSA-2024:0009 |
| Red Hat Enterprise Linux 8 | tigervnc-0:1.13.1-2.el8_9.4 | Fixed | RHSA-2024:0018 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-0:1.20.11-22.el8 | Fixed | RHSA-2024:2995 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland-0:21.1.3-15.el8 | Fixed | RHSA-2024:2996 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | tigervnc-0:1.9.0-15.el8_2.6 | Fixed | RHSA-2024:0017 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | tigervnc-0:1.9.0-15.el8_2.6 | Fixed | RHSA-2024:0017 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | tigervnc-0:1.9.0-15.el8_2.6 | Fixed | RHSA-2024:0017 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | tigervnc-0:1.11.0-8.el8_4.5 | Fixed | RHSA-2024:0016 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | tigervnc-0:1.11.0-8.el8_4.5 | Fixed | RHSA-2024:0016 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | tigervnc-0:1.11.0-8.el8_4.5 | Fixed | RHSA-2024:0016 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | tigervnc-0:1.12.0-6.el8_6.6 | Fixed | RHSA-2024:0015 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | tigervnc-0:1.12.0-15.el8_8.4 | Fixed | RHSA-2024:0014 |
| Red Hat Enterprise Linux 9 | tigervnc-0:1.13.1-3.el9_3.3 | Fixed | RHSA-2024:0010 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-0:1.20.11-24.el9 | Fixed | RHSA-2024:2169 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland-0:22.1.9-5.el9 | Fixed | RHSA-2024:2170 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | tigervnc-0:1.11.0-22.el9_0.5 | Fixed | RHSA-2024:0020 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | tigervnc-0:1.12.0-14.el9_2.2 | Fixed | RHSA-2023:7886 |
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore, Red Hat Enterprise Linux 8 and 9 have been rated with a moderate severity.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (31)
- http://www.openwall.com/lists/oss-security/2023/12/13/1
- https://access.redhat.com/errata/RHSA-2023:7886 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2024:0006 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0009 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0010 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0014 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0015 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0016 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0017 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0018 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0020 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2169 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2170 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2995 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2996 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:12751 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6478 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2253298 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58711 Advisory
- https://gitlab.freedesktop.org/xorg/xserver/-/commit/14f480010a93ff962fef66a16412fafff81ad632 Patch
- https://lists.debian.org/debian-lts-announce/2023/12/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6R63Z6GIWM3YUNZRCGFODUXLW3GY2HD6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PP47YXKM5ETLCYEF6473R3VFCJ6QT2S/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFHV5KCQ2SVOD4QMCPZ5HC6YL44L7YJD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LJDFWDB7EQVZA45XDP7L5WRSRWS6RVRR/
- https://lists.x.org/archives/xorg-announce/2023-December/003435.html Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-6478
- https://security.gentoo.org/glsa/202401-30
- https://security.netapp.com/advisory/ntap-20240125-0003/
- https://www.cve.org/CVERecord?id=CVE-2023-6478
- https://www.debian.org/security/2023/dsa-5576
Change history (0)
No recorded changes yet.