CVE-2023-6816: Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.
Other sources
Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255 but the X.Org Server was only allocating space for the device's number of buttons, leading to a heap overflow if a bigger value was used.
— Red Hat
Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer
— Microsoft
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6816?
CVE-2023-6816 has been classified with a moderate severity rating.
How do I fix CVE-2023-6816?
To fix CVE-2023-6816, upgrade to xorg-server version 21.1.11 or xwayland version 23.2.4 or later.
What software does CVE-2023-6816 affect?
CVE-2023-6816 affects xorg-server and xwayland on specific versions of Red Hat and Debian systems.
What type of vulnerability is CVE-2023-6816?
CVE-2023-6816 is a flaw that allows for arbitrary button mapping in the X.Org server.
Is there a patch available for CVE-2023-6816?
Yes, patches have been released for the affected versions of xorg-server and xwayland.