CVE-2023-43786: Libx11: stack exhaustion from infinite recursion in putsubimage()
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
Other sources
A vulnerability was found in libX11 where the vulnerability exists due to infinite loop within the PutSubImage() function, a local user can consume all available system resources and cause denial of service conditions.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43786?
CVE-2023-43786 is a vulnerability in libX11 that allows for stack exhaustion from infinite recursion in PutSubImage().
How does CVE-2023-43786 affect libX11?
CVE-2023-43786 affects libX11 versions 1.8.7 and earlier, 2:1.6.9-2ubuntu1.6 and earlier, 2:1.7.5-1ubuntu0.3 and earlier, and 2:1.8.4-2ubuntu0.3 and earlier.
How severe is CVE-2023-43786?
CVE-2023-43786 is considered a serious vulnerability.
Where can I find more information about CVE-2023-43786?
More information about CVE-2023-43786 can be found on the MITRE CVE website and the Ubuntu security notices USN-6407-1 and USN-6408-1.
How can I fix CVE-2023-43786?
To fix CVE-2023-43786, update to libX11 version 1.8.7 or later, 2:1.6.9-2ubuntu1.6 or later, 2:1.7.5-1ubuntu0.3 or later, or 2:1.8.4-2ubuntu0.3 or later.