CVE-2023-5574
HIGHX.org X Server - Use After Free
Title source: ruleDescription
A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.
References (5)
Scores
CVSS v3
7.0
EPSS
0.0003
EPSS Percentile
9.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-416
Status
published
Affected Products (2)
x.org/x_server
redhat/enterprise_linux
Timeline
Published
Oct 25, 2023
Tracked Since
Feb 18, 2026