CVE-2023-6377: Xorg-x11-server: out-of-bounds memory reads/writes in xkb button actions
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
Other sources
CVE-2023-6377: X.Org server: Out-of-bounds memory write in XKB button actions
Introduced in: xorg-server-1.6.0 (2009) Fixed in: xorg-server-21.1.10 and xwayland-23.2.3 Found by: Jan-Niklas Sohn working with Trend Micro Zero Day Initiative
A device has XKB button actions for each button on the device. When a logical device switch happens (e.g. moving from a touchpad to a mouse), the server re-calculates the information available on the respective master device (typically the Virtual Core Pointer). This re-calculation only allocated enough memory for a single XKB action rather instead of enough for the newly active physical device's number of button. As a result, querying or changing the XKB button actions results in out-of-bounds memory reads and writes.
This may lead to local privilege escalation if the server is run as root or remote code execution (e.g. x11 over ssh).
xorg-server-21.1.10 and xwayland-23.2.3 have been patched to fix this issue.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xorg-serverto a version that resolves this vulnerability.Fixed in 2:1.20.11-1+deb11u13Fixed in 2:1.20.11-1+deb11u15Fixed in 2:21.1.7-3+deb12u9Fixed in 2:21.1.16-1 - Upgrade
Upgrade
debian/xwaylandto a version that resolves this vulnerability.Fixed in 2:24.1.6-1 - Upgrade
Upgrade
redhat/xorg-serverto a version that resolves this vulnerability.Fixed in 21.1.10 - Upgrade
Upgrade
redhat/xwaylandto a version that resolves this vulnerability.Fixed in 23.2.3 - Upgrade
Upgrade
debian/xorg-serverto a version that resolves this vulnerability.Fixed in 2:1.20.11-1+deb11u13 - Upgrade
Upgrade
debian/xorg-serverto a version that resolves this vulnerability.Fixed in 2:1.20.11-1+deb11u15 - Upgrade
Upgrade
debian/xorg-serverto a version that resolves this vulnerability.Fixed in 2:21.1.7-3+deb12u9 - Upgrade
Upgrade
debian/xorg-serverto a version that resolves this vulnerability.Fixed in 2:21.1.16-1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6377?
CVE-2023-6377 has been classified as a high severity vulnerability due to its potential for local privilege escalation and remote code execution.
How do I fix CVE-2023-6377?
To fix CVE-2023-6377, update xorg-server to version 21.1.10 or later, and xwayland to version 23.2.3 or later on affected systems.
Which software is affected by CVE-2023-6377?
CVE-2023-6377 affects xorg-server versions prior to 21.1.10 and xwayland versions prior to 23.2.3 on specific Red Hat and Debian distributions.
Can CVE-2023-6377 be exploited remotely?
Yes, CVE-2023-6377 may allow remote code execution in scenarios involving X11 forwarding.
What are the consequences of CVE-2023-6377 if exploited?
If exploited, CVE-2023-6377 could lead to unauthorized access and control over affected systems, resulting in potential data breaches or system compromise.