CVE-2023-5380 is a use-after-free vulnerability in the xorg-x11-server, affecting Debian, Fedora, Red Hat, and X.Org. This medium-severity flaw (CVSS 4.7) requires a very specific and legacy multi-screen configuration (Zaphod mode) and a precise sequence of actions to trigger a server crash. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.1.9CPE matchmatch criteria | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* | ||
< 23.2.2CPE matchmatch criteria | cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024xorg-x11-server: Use-after-free bug in DestroyWindow
Oct 25, 2023Xorg-x11-server: use-after-free bug in destroywindow
Oct 10, 2023