---
id: CVE-2023-5367
title: A out-of-bounds write flaw was found in the xorg-x11-server
summary: >-
  A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs
  due to an incorrect calculation of a buffer offset when copying data stored in
  the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in
  RRCha…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
  - CWE-787
vendor: x.org
product: x_server
affected:
  - x_server < 21.1.9
  - xwayland < 23.2.2
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux_desktop = 7.0
  - enterprise_linux_for_ibm_z_systems = 7.0_s390x
  - enterprise_linux_for_power_big_endian = 7.0_ppc64
  - enterprise_linux_for_power_little_endian = 7.0_ppc64le
  - enterprise_linux_for_scientific_computing = 7.0
  - enterprise_linux_server = 7.0
  - enterprise_linux_workstation = 7.0
  - fedora = 37
  - fedora = 38
  - fedora = 39
  - debian_linux = 11.0
  - debian_linux = 12.0
patched:
  - x_server 21.1.9
  - xwayland 23.2.2
published: '2023-10-25'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-5367'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2023:6802'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:6808'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7373'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7388'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7405'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7428'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7436'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7526'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7533'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0010'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0128'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2169'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2170'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2995'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2996'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12751'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-5367'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2243091'
    label: secalert@redhat.com
  - url: 'https://lists.x.org/archives/xorg-announce/2023-October/003430.html'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:6802'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:6808'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7373'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7388'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7405'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7428'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7436'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7526'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7533'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0010'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0128'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2169'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2170'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2995'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2996'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-5367'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2243091'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00036.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WS5E7H4A5J3U5YBCTMRPQVGWK5LVH7D/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3RK66CXMXO3PCPDU3GDY5FK4UYHUXQJT/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4YBK3I6SETHETBHDETFWM3VSZUQICIDV/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKKIE626TZOOPD533EYN47J4RFNHZVOP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HO2Q2NP6R62ZRQQG3XQ4AXUT7J2EKKKY/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L2RMNR4235YXZZQ2X7Q4MTOZDMZ7BBQU/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SEDJN4VFN57K5POOC7BNVD6L6WUUCSG6/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SN6KV4XGQJRVAOSM5C3CWMVAXO53COIP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJXNI4BXURC2BKPNAHFJK3C5ZETB7PER/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.x.org/archives/xorg-announce/2023-October/003430.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202401-30'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20231130-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5534'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0062
epssPercentile: 0.48019
ingestedAt: '2026-06-29T13:24:33.912Z'
---

## Overview

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.

## Affected

- `x_server < 21.1.9`
- `xwayland < 23.2.2`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux_desktop = 7.0`
- `enterprise_linux_for_ibm_z_systems = 7.0_s390x`
- `enterprise_linux_for_power_big_endian = 7.0_ppc64`
- `enterprise_linux_for_power_little_endian = 7.0_ppc64le`
- `enterprise_linux_for_scientific_computing = 7.0`
- `enterprise_linux_server = 7.0`
- `enterprise_linux_workstation = 7.0`
- `fedora = 37`
- `fedora = 38`
- `fedora = 39`
- `debian_linux = 11.0`
- `debian_linux = 12.0`

## Remediation

Upgrade past the affected range:

- `x_server 21.1.9`
- `xwayland 23.2.2`
