CVE-2023-6478: Debian Linux

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
  • Red Hat Enterprise Linux Eus: version 9.2 only
  • Tigervnc Tigervnc: affected versions not specified
  • X.org X Server: before 21.1.10 (fixed in 21.1.10)
  • X.org Xwayland: before 23.2.3 (fixed in 23.2.3)

Published 2023-12-13. Last modified 2026-06-23.