CVE-2023-6377

Updated: 2026-02-27 01:14:59.93492

Description:

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU xorg-x11-server-Xwayland 21.1.3 7.8 HIGH Released CLSA-2025:1763558418 2025-11-19 17:09:35
AlmaLinux 9.2 ESU tigervnc 1.12.0 7.8 HIGH Released CLSA-2025:1744632481 2025-04-15 03:59:53