CVE-2023-0494: Use After Free
CVE-2023-0494/ZDI-CAN-19596: X.Org Server DeepCopyPointerClasses use-after-free
A dangling pointer in DeepCopyPointerClasses can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read/write into freed memory.
Other sources
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0494?
The severity of CVE-2023-0494 is high with a CVSS score of 7.8.
Which software is affected by CVE-2023-0494?
The software affected by CVE-2023-0494 includes X.Org X Server, xorg-server, and various versions of Fedora and Redhat Enterprise Linux.
How can CVE-2023-0494 be exploited?
CVE-2023-0494 can be exploited by using the ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() functions to read and write into freed memory, leading to local privilege elevation.
How can I fix CVE-2023-0494?
To fix CVE-2023-0494, update to version 21.1.7 of xorg-server.
Where can I find more information about CVE-2023-0494?
More information about CVE-2023-0494 can be found in the X.Org announcement and the Redhat bugzilla links provided.