CVE-2023-6377: Debian Linux
High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
- Red Hat Enterprise Linux Eus: version 9.2 only
- Tigervnc Tigervnc: affected versions not specified
- X.org X Server: before 21.1.10 (fixed in 21.1.10)
- X.org Xwayland: before 23.2.3 (fixed in 23.2.3)
Published 2023-12-13. Last modified 2026-06-23.