CVE-2023-6478: Debian Linux
High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
- Red Hat Enterprise Linux Eus: version 9.2 only
- Tigervnc Tigervnc: affected versions not specified
- X.org X Server: before 21.1.10 (fixed in 21.1.10)
- X.org Xwayland: before 23.2.3 (fixed in 23.2.3)
Published 2023-12-13. Last modified 2026-06-23.