---
id: CVE-2023-5380
title: A use-after-free flaw was found in the xorg-x11-server
summary: >-
  A use-after-free flaw was found in the xorg-x11-server. An X server crash may
  occur in a very specific and legacy configuration (a multi-screen setup with
  multiple protocol screens, also known as Zaphod mode) if the pointer is warped
  fro…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-416
  - CWE-416
vendor: x.org
product: x_server
affected:
  - x_server < 21.1.9
  - xwayland < 23.2.2
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - fedora = 37
  - fedora = 38
  - fedora = 39
  - debian_linux = 11.0
  - debian_linux = 12.0
patched:
  - x_server 21.1.9
  - xwayland 23.2.2
published: '2023-10-25'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-5380'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2023:7428'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2169'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2298'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2995'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:3067'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-5380'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2244736'
    label: secalert@redhat.com
  - url: 'https://lists.x.org/archives/xorg-announce/2023-October/003430.html'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7428'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2169'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2298'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2995'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:3067'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-5380'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2244736'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00036.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WS5E7H4A5J3U5YBCTMRPQVGWK5LVH7D/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3RK66CXMXO3PCPDU3GDY5FK4UYHUXQJT/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AKKIE626TZOOPD533EYN47J4RFNHZVOP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HO2Q2NP6R62ZRQQG3XQ4AXUT7J2EKKKY/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SN6KV4XGQJRVAOSM5C3CWMVAXO53COIP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJXNI4BXURC2BKPNAHFJK3C5ZETB7PER/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.x.org/archives/xorg-announce/2023-October/003430.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202401-30'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20231130-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5534'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00715
epssPercentile: 0.52291
ingestedAt: '2026-06-29T13:24:33.915Z'
---

## Overview

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

## Affected

- `x_server < 21.1.9`
- `xwayland < 23.2.2`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `fedora = 37`
- `fedora = 38`
- `fedora = 39`
- `debian_linux = 11.0`
- `debian_linux = 12.0`

## Remediation

Upgrade past the affected range:

- `x_server 21.1.9`
- `xwayland 23.2.2`
