CVE-2023-5380Medium· 4.7▾ SunlitA use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped fro…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
x_server < 21.1.9xwayland < 23.2.2enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0fedora = 37fedora = 38fedora = 39debian_linux = 11.0debian_linux = 12.0Upgrade past the affected range:
x_server 21.1.9xwayland 23.2.2Connected by shared product, vendor, weakness, or advisory.
CVE-2023-5574High· 7.0A use-after-free flaw was found in xorg-x11-server-Xvfb
CVE-2023-6478High· 7.6A flaw was found in xorg-server
CVE-2023-6377High· 7.8A flaw was found in xorg-server
CVE-2023-5367High· 7.8A out-of-bounds write flaw was found in the xorg-x11-server
CVE-2026-50261High· 7.8A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter()
CVE-2026-50260High· 7.8A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter()