A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
2023-10-25T20:15:18.323
2025-11-04T20:17:13.090
Modified
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | x.org | x_server | < 21.1.9 | Yes |
| Application | x.org | xwayland | < 23.2.2 | Yes |
| Operating System | redhat | enterprise_linux | 7.0 | Yes |
| Operating System | redhat | enterprise_linux | 8.0 | Yes |
| Operating System | redhat | enterprise_linux | 9.0 | Yes |
| Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
| Operating System | redhat | enterprise_linux_for_ibm_z_systems | 7.0_s390x | Yes |
| Operating System | redhat | enterprise_linux_for_power_big_endian | 7.0_ppc64 | Yes |
| Operating System | redhat | enterprise_linux_for_power_little_endian | 7.0_ppc64le | Yes |
| Operating System | redhat | enterprise_linux_for_scientific_computing | 7.0 | Yes |
| Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
| Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
| Operating System | fedoraproject | fedora | 37 | Yes |
| Operating System | fedoraproject | fedora | 38 | Yes |
| Operating System | fedoraproject | fedora | 39 | Yes |
| Operating System | debian | debian_linux | 11.0 | Yes |
| Operating System | debian | debian_linux | 12.0 | Yes |