First published: Thu Mar 30 2023(Updated: )
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
X.org Xorg-server | <21.1.8 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-1393 is high.
CVE-2023-1393 leads to local privilege escalation through a Use-After-Free vulnerability in X.Org Server Overlay Window.
CVE-2023-1393 affects X.Org Server versions up to and excluding 21.1.8, Fedora 36, Fedora 37, and Fedora 38.
To fix CVE-2023-1393, users should update to the patched version of X.Org Server and apply any available security patches or updates provided by their operating system.
The CWE of CVE-2023-1393 is CWE-416: Use After Free.