---
id: CVE-2023-6377
title: A flaw was found in xorg-server
summary: >-
  A flaw was found in xorg-server. Querying or changing XKB button actions such
  as moving from a touchpad to a mouse can result in out-of-bounds memory reads
  and writes. This may allow local privilege escalation or possible remote code
  exe…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
  - CWE-125
vendor: x.org
product: x_server
affected:
  - enterprise_linux_eus = 9.2
  - debian_linux = 10.0
  - debian_linux = 11.0
  - debian_linux = 12.0
  - x_server < 21.1.10
  - xwayland < 23.2.3
  - tigervnc
patched:
  - x_server 21.1.10
  - xwayland 23.2.3
published: '2023-12-13'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-6377'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2023:7886'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0006'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0009'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0010'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0014'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0015'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0016'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0017'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0018'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0020'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2169'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2170'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2995'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2996'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13998'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-6377'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2253291'
    label: secalert@redhat.com
  - url: >-
      https://gitlab.freedesktop.org/xorg/xserver/-/commit/0c1a93d319558fe3ab2d94f51d174b4f93810afd
    label: secalert@redhat.com
  - url: 'https://lists.x.org/archives/xorg-announce/2023-December/003435.html'
    label: secalert@redhat.com
  - url: 'http://www.openwall.com/lists/oss-security/2023/12/13/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7886'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0006'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0009'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0010'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0014'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0015'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0016'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0017'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0018'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0020'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2169'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2170'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2995'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2996'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-6377'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2253291'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://gitlab.freedesktop.org/xorg/xserver/-/commit/0c1a93d319558fe3ab2d94f51d174b4f93810afd
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/12/msg00008.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/12/msg00013.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6R63Z6GIWM3YUNZRCGFODUXLW3GY2HD6/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PP47YXKM5ETLCYEF6473R3VFCJ6QT2S/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFHV5KCQ2SVOD4QMCPZ5HC6YL44L7YJD/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LJDFWDB7EQVZA45XDP7L5WRSRWS6RVRR/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.x.org/archives/xorg-announce/2023-December/003435.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202401-30'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20240125-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5576'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01574
epssPercentile: 0.74375
ingestedAt: '2026-06-29T13:24:33.948Z'
---

## Overview

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

## Affected

- `enterprise_linux_eus = 9.2`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `debian_linux = 12.0`
- `x_server < 21.1.10`
- `xwayland < 23.2.3`
- `tigervnc`

## Remediation

Upgrade past the affected range:

- `x_server 21.1.10`
- `xwayland 23.2.3`
