← Back

CVE-2023-0494

nvd nist
Published: Mar 27, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.

Affected (35)

1 product
X Server
1 product
Fedora
16 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 21.1.7
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 36
Version 37
Configuration C
32 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 8.0
Version 8.1
Version 9.0
Redhat
Version 8.4
Version 8.6
Version 7.0
Redhat
Version 8.4
Version 8.6
Version 9.0
Redhat
Version 7.0
Version 8.0
Redhat
Version 8.4
Version 8.6
Version 7.0
Redhat
Version 7.0
Version 8.0
Version 9.0
Redhat
Version 8.4
Version 8.6
Version 7.0
Version 7.0
Version 8.2
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 9.0
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 8.2
Version 7.0

References (8)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.