CVE-2023-1393
Summary
| CVE | CVE-2023-1393 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-30 21:15:00 UTC |
| Updated | 2023-11-07 04:03:00 UTC |
| Description | A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| X.Org X server, XWayland: Multiple Vulnerabilities (GLSA 202305-30) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 36 Update: tigervnc-1.13.1-3.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: xorg-x11-server-Xwayland-22.1.9-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: xorg-x11-server-1.20.14-21.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: tigervnc-1.13.1-3.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| composite: Fix use-after-free of the COW (26ef545b) · Commits · xorg / xserver · GitLab |
MISC |
gitlab.freedesktop.org |
|
| [SECURITY] Fedora 37 Update: xorg-x11-server-Xwayland-22.1.9-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: xorg-x11-server-Xwayland-22.1.9-1.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: xorg-x11-server-Xwayland-22.1.9-1.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: xorg-x11-server-1.20.14-21.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: xorg-x11-server-Xwayland-22.1.9-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: xorg-x11-server-1.20.14-21.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: tigervnc-1.13.1-3.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: tigervnc-1.13.1-3.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: xorg-x11-server-1.20.14-21.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: tigervnc-1.13.1-3.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: xorg-x11-server-Xwayland-22.1.9-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: tigervnc-1.13.1-3.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-security - Fwd: X.Org Security Advisory: CVE-2023-1393: X.Org Server Overlay
Window Use-After-Free |
MISC |
www.openwall.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160529 Oracle Enterprise Linux Security Update for tigervnc (ELSA-2023-1551)
- 160530 Oracle Enterprise Linux Security Update for tigervnc (ELSA-2023-1592)
- 160531 Oracle Enterprise Linux Security Update for tigervnc and xorg-x11-server (ELSA-2023-1594)
- 161087 Oracle Enterprise Linux Security Update for xorg-x11-server-xwayland (ELSA-2023-6341)
- 161089 Oracle Enterprise Linux Security Update for xorg-x11-server (ELSA-2023-6340)
- 161174 Oracle Enterprise Linux Security Update for xorg-x11-server-xwayland (ELSA-2023-6917)
- 161186 Oracle Enterprise Linux Security Update for xorg-x11-server (ELSA-2023-6916)
- 181642 Debian Security Update for xorg-server (DLA 3372-1)
- 181673 Debian Security Update for xorg-server (DSA 5380-1)
- 182564 Debian Security Update for xwaylandxorg-server (CVE-2023-1393)
- 199263 Ubuntu Security Notification for X.Org X Server Vulnerability (USN-5986-1)
- 241309 Red Hat Update for tigervnc (RHSA-2023:1551)
- 241312 Red Hat Update for tigervnc (RHSA-2023:1592)
- 241317 Red Hat Update for tigervnc (RHSA-2023:1599)
- 241318 Red Hat Update for tigervnc (RHSA-2023:1598)
- 241319 Red Hat Update for tigervnc and xorg-x11-server (RHSA-2023:1594)
- 241333 Red Hat Update for tigervnc (RHSA-2023:1548)
- 241635 Red Hat Update for tigervnc (RHSA-2023:1549)
- 241666 Red Hat Update for tigervnc (RHSA-2023:1600)
- 242279 Red Hat Update for xorg-x11-server-xwayland security (RHSA-2023:6341)
- 242298 Red Hat Update for xorg-x11-server (RHSA-2023:6340)
- 242418 Red Hat Update for xorg-x11-server (RHSA-2023:6916)
- 242454 Red Hat Update for xorg-x11-server-xwayland (RHSA-2023:6917)
- 283826 Fedora Security Update for xorg (FEDORA-2023-7d7c74b868)
- 283840 Fedora Security Update for xorg (FEDORA-2023-eb3c27ff25)
- 283851 Fedora Security Update for tigervnc (FEDORA-2023-66d5af0278)
- 283888 Fedora Security Update for xorg (FEDORA-2023-fe18ae3e85)
- 283889 Fedora Security Update for xorg (FEDORA-2023-239bae4b57)
- 283892 Fedora Security Update for tigervnc (FEDORA-2023-6f3f9ee721)
- 284212 Fedora Security Update for tigervnc (FEDORA-2023-b87fd3a628)
- 284215 Fedora Security Update for xorg (FEDORA-2023-b7835960ac)
- 284216 Fedora Security Update for xorg (FEDORA-2023-f754e7abfd)
- 378422 Alibaba Cloud Linux Security Update for tigervnc and xorg-x11-server (ALINUX2-SA-2023:0017)
- 379255 Alibaba Cloud Linux Security Update for xorg-x11-server (ALINUX3-SA-2024:0010)
- 379627 Alibaba Cloud Linux Security Update for xorg-x11-server-xwayland (ALINUX3-SA-2024:0044)
- 673369 EulerOS Security Update for xorg-x11-server (EulerOS-SA-2023-2673)
- 673442 EulerOS Security Update for xorg-x11-server (EulerOS-SA-2024-1307)
- 673924 EulerOS Security Update for tigervnc (EulerOS-SA-2024-1304)
- 673933 EulerOS Security Update for xorg-x11-server (EulerOS-SA-2023-2715)
- 691103 Free Berkeley Software Distribution (FreeBSD) Security Update for xorg (96d84238-b500-490b-b6aa-2b77090a0410)
- 710738 Gentoo Linux X.Org X server, XWayland Multiple Vulnerabilities (GLSA 202305-30)
- 753851 SUSE Enterprise Linux Security Update for xorg-x11-server (SUSE-SU-2023:1679-1)
- 753853 SUSE Enterprise Linux Security Update for xorg-x11-server (SUSE-SU-2023:1677-1)
- 753871 SUSE Enterprise Linux Security Update for xorg-x11-server (SUSE-SU-2023:1678-1)
- 753872 SUSE Enterprise Linux Security Update for xorg-x11-server (SUSE-SU-2023:1674-1)
- 940972 AlmaLinux Security Update for tigervnc (ALSA-2023:1592)
- 940975 AlmaLinux Security Update for tigervnc (ALSA-2023:1551)
- 941390 AlmaLinux Security Update for xorg-x11-server (ALSA-2023:6340)
- 941394 AlmaLinux Security Update for xorg-x11-server-Xwayland (ALSA-2023:6341)
- 941433 AlmaLinux Security Update for xorg-x11-server (ALSA-2023:6916)
- 941471 AlmaLinux Security Update for xorg-x11-server-Xwayland (ALSA-2023:6917)
- 960900 Rocky Linux Security Update for tigervnc (RLSA-2023:1592)