CVE-2023-1393: Use After Free
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW) the Xserver would leave a dangling pointer to that window in the CompScreen structure which will trigger a use-after-free later.
Other sources
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
ZDI-CAN-19866/CVE-2023-1393: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability
If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1393?
The severity of CVE-2023-1393 is high.
How does CVE-2023-1393 lead to local privilege escalation?
CVE-2023-1393 leads to local privilege escalation through a Use-After-Free vulnerability in X.Org Server Overlay Window.
Which software versions are affected by CVE-2023-1393?
CVE-2023-1393 affects X.Org Server versions up to and excluding 21.1.8, Fedora 36, Fedora 37, and Fedora 38.
How can I fix CVE-2023-1393?
To fix CVE-2023-1393, users should update to the patched version of X.Org Server and apply any available security patches or updates provided by their operating system.
What is the Common Weakness Enumeration (CWE) of CVE-2023-1393?
The CWE of CVE-2023-1393 is CWE-416: Use After Free.