CVE-2023-5367: Debian Linux
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
Affected products
- Debian Debian Linux: version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux For IBM Z Systems: version 7.0_s390x only
- Red Hat Enterprise Linux For Power Big Endian: version 7.0_ppc64 only
- Red Hat Enterprise Linux For Power Little Endian: version 7.0_ppc64le only
- Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- X.org X Server: before 21.1.9 (fixed in 21.1.9)
- X.org Xwayland: before 23.2.2 (fixed in 23.2.2)
Published 2023-10-25. Last modified 2026-06-23.