Xorg-x11-server: use-after-free bug in damagedestroy
Summary
| CVE | CVE-2023-5574 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-25 20:15:18 UTC |
| Updated | 2026-06-23 18:17:37 UTC |
| Description | A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service. |
Risk And Classification
Primary CVSS: v3.1 7 HIGH from [email protected]
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.005360000 probability, percentile 0.411340000 (date 2026-06-28)
Problem Types: CWE-416 | CWE-416 Use After Free
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Application | X.org | X Server | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:1.13.1-8.el9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| X.Org Security Advisory: Issues in X.Org X server prior to 21.1.9 and Xwayland prior to 23.2.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.x.org | Patch, Vendor Advisory |
| security.netapp.com/advisory/ntap-20231130-0004 | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | |
| 2244735 – (CVE-2023-5574) CVE-2023-5574 xorg-x11-server: Use-after-free bug in DamageDestroy | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:2298 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| cve-details | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-10-17T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2023-10-25T00:00:00.000Z | Made public. |
Workarounds
CNA: Starting Xvfb with the -noreset command line option limits the use-after-free from being triggered only at the Xvfb server shutdown. Also, do not start Xvfb as root.
Legacy QID Mappings
- 296108 Oracle Solaris 11.4 Support Repository Update (SRU) 66.164.1 Missing (CPUJAN2024)
- 356766 Amazon Linux Security Advisory for xorg-x11-server : ALAS2-2023-2352
- 356784 Amazon Linux Security Advisory for xorg-x11-server : ALAS-2023-1892
- 356904 Amazon Linux Security Advisory for xorg-x11-server : ALAS2023-2023-444
- 356994 Amazon Linux Security Advisory for xorg-x11-server : AL2012-2023-478
- 503445 Alpine Linux Security Update for xorg-server
- 506278 Alpine Linux Security Update for xorg-server
- 755188 SUSE Enterprise Linux Security Update for xorg-x11-server (SUSE-SU-2023:4272-1)
- 755191 SUSE Enterprise Linux Security Update for xorg-x11-server (SUSE-SU-2023:4269-1)
- 755198 SUSE Enterprise Linux Security Update for xwayland (SUSE-SU-2023:4306-1)
- 755203 SUSE Enterprise Linux Security Update for xwayland (SUSE-SU-2023:4293-1)
- 755204 SUSE Enterprise Linux Security Update for xorg-x11-server (SUSE-SU-2023:4292-1)
- 755217 SUSE Enterprise Linux Security Update for xorg-x11-server (SUSE-SU-2023:4338-1)