{"id":"CVE-2023-6377","title":"A flaw was found in xorg-server","summary":"A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code exe…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-125","CWE-125"],"vendor":"x.org","product":"x_server","affected":["enterprise_linux_eus = 9.2","debian_linux = 10.0","debian_linux = 11.0","debian_linux = 12.0","x_server < 21.1.10","xwayland < 23.2.3","tigervnc"],"patched":["x_server 21.1.10","xwayland 23.2.3"],"published":"2023-12-13","updated":"2026-06-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-6377","references":[{"url":"https://access.redhat.com/errata/RHSA-2023:7886","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0006","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0009","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0010","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0014","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0015","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0016","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0017","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0018","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0020","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2169","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2170","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2995","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2996","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:13998","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2023-6377","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2253291","label":"secalert@redhat.com"},{"url":"https://gitlab.freedesktop.org/xorg/xserver/-/commit/0c1a93d319558fe3ab2d94f51d174b4f93810afd","label":"secalert@redhat.com"},{"url":"https://lists.x.org/archives/xorg-announce/2023-December/003435.html","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2023/12/13/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7886","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0006","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0009","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0010","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0014","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0015","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0016","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0017","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0018","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0020","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2169","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2170","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2995","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2996","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2023-6377","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2253291","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gitlab.freedesktop.org/xorg/xserver/-/commit/0c1a93d319558fe3ab2d94f51d174b4f93810afd","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00008.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00013.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6R63Z6GIWM3YUNZRCGFODUXLW3GY2HD6/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PP47YXKM5ETLCYEF6473R3VFCJ6QT2S/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFHV5KCQ2SVOD4QMCPZ5HC6YL44L7YJD/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LJDFWDB7EQVZA45XDP7L5WRSRWS6RVRR/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.x.org/archives/xorg-announce/2023-December/003435.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202401-30","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20240125-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2023/dsa-5576","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01574,"epssPercentile":0.74335,"ingestedAt":"2026-06-29T13:24:33.948Z","slug":"CVE-2023-6377","body":"## Overview\n\nA flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.\n\n## Affected\n\n- `enterprise_linux_eus = 9.2`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `debian_linux = 12.0`\n- `x_server < 21.1.10`\n- `xwayland < 23.2.3`\n- `tigervnc`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `x_server 21.1.10`\n- `xwayland 23.2.3`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}