CVE-2023-6816

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-6816
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6816.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-6816
Related
Published
2024-01-18T05:15:08Z
Modified
2025-04-29T08:05:47.560061Z
Downstream
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.

References

Affected packages

Debian:11 / xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.20.11-1+deb11u11

Affected versions

2:1.*

2:1.20.11-1
2:1.20.11-1+deb11u1
2:1.20.11-1+deb11u2
2:1.20.11-1+deb11u3
2:1.20.11-1+deb11u4
2:1.20.11-1+deb11u5
2:1.20.11-1+deb11u6
2:1.20.11-1+deb11u7
2:1.20.11-1+deb11u8
2:1.20.11-1+deb11u9
2:1.20.11-1+deb11u10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.1.7-3+deb12u5

Affected versions

2:21.*

2:21.1.7-3
2:21.1.7-3+deb12u1
2:21.1.7-3+deb12u2
2:21.1.7-3+deb12u3
2:21.1.7-3+deb12u4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.1.11-1

Affected versions

2:21.*

2:21.1.7-3
2:21.1.8-1
2:21.1.9-1
2:21.1.9-1+hurd.1
2:21.1.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / xwayland

Package

Name
xwayland
Purl
pkg:deb/debian/xwayland?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:22.*

2:22.1.9-1

2:23.*

2:23.1.0-1
2:23.1.1-1
2:23.2.0-1
2:23.2.1-1
2:23.2.2-1
2:23.2.3-1
2:23.2.4-1
2:23.2.6-1

2:24.*

2:24.0.99.901-1
2:24.1.0-1
2:24.1.2-1
2:24.1.3-1
2:24.1.4-1
2:24.1.4-2
2:24.1.4-3
2:24.1.5-1
2:24.1.6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / xwayland

Package

Name
xwayland
Purl
pkg:deb/debian/xwayland?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:23.2.4-1

Affected versions

2:22.*

2:22.1.9-1

2:23.*

2:23.1.0-1
2:23.1.1-1
2:23.2.0-1
2:23.2.1-1
2:23.2.2-1
2:23.2.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}