Aller au contenu

Fiche vulnérabilité

CVE-2023-6816 : faille critique x.org x server (CVSS 9.8)

Description

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
18 janv. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • x.org x server
  • x.org xwayland
  • fedoraproject fedora
  • redhat enterprise linux desktop
  • redhat enterprise linux server
  • redhat enterprise linux workstation
  • debian debian linux

Références

Rechercher une autre vulnérabilité dans la base CVE