CVE-2023-6377High· 7.8▾ TwilightA flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code exe…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.6%
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
enterprise_linux_eus = 9.2debian_linux = 10.0debian_linux = 11.0debian_linux = 12.0x_server < 21.1.10xwayland < 23.2.3tigervncUpgrade past the affected range:
x_server 21.1.10xwayland 23.2.3Connected by shared product, vendor, weakness, or advisory.
CVE-2023-6478High· 7.6A flaw was found in xorg-server
CVE-2023-5380Medium· 4.7A use-after-free flaw was found in the xorg-x11-server
CVE-2023-5367High· 7.8A out-of-bounds write flaw was found in the xorg-x11-server
CVE-2026-50262Medium· 5.5An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes()
CVE-2026-50264High· 7.8An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat
CVE-2026-50263Medium· 5.5A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow()