CVE-2023-5380: Debian Linux
Medium severity, CVSS 4.7. EPSS: 0.7% chance of exploitation in the next 30 days.
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
Affected products
- Debian Debian Linux: version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only
- X.org X Server: before 21.1.9 (fixed in 21.1.9)
- X.org Xwayland: before 23.2.2 (fixed in 23.2.2)
Published 2023-10-25. Last modified 2026-06-23.