CVE-2023-5574

NameCVE-2023-5574
DescriptionA use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1055426

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xorg-server (PTS)jessie, jessie (lts)2:1.16.4-1+deb8u17vulnerable
stretch (security)2:1.19.2-1+deb9u9vulnerable
stretch (lts), stretch2:1.19.2-1+deb9u20vulnerable
buster, buster (lts)2:1.20.4-1+deb10u15vulnerable
buster (security)2:1.20.4-1+deb10u14vulnerable
bullseye2:1.20.11-1+deb11u13vulnerable
bullseye (security)2:1.20.11-1+deb11u14vulnerable
bookworm (security), bookworm2:21.1.7-3+deb12u8vulnerable
sid, trixie2:21.1.14-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xorg-serversource(unstable)(unfixed)1055426

Notes

[bookworm] - xorg-server <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - xorg-server <no-dsa> (Minor issue)
[buster] - xorg-server <no-dsa> (Minor issue)
https://lists.x.org/archives/xorg-announce/2023-October/003430.html
https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1189
[stretch] - xorg-server <no-dsa> (Minor issue)
[jessie] - xorg-server <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems