CVE-2023-6377: Debian Linux

High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
  • Red Hat Enterprise Linux Eus: version 9.2 only
  • Tigervnc Tigervnc: affected versions not specified
  • X.org X Server: before 21.1.10 (fixed in 21.1.10)
  • X.org Xwayland: before 23.2.3 (fixed in 23.2.3)

Published 2023-12-13. Last modified 2026-06-23.