A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
[ { "signature_type": "Function", "deprecated": false, "source": "https://gitlab.freedesktop.org/xorg/xserver@26ef545b3502f61ca722a7a3373507e88ef64110", "signature_version": "v1", "target": { "function": "compDestroyWindow", "file": "composite/compwindow.c" }, "digest": { "function_hash": "160585413429378803102572218228695144404", "length": 657.0 }, "id": "CVE-2023-1393-1b85dd2e" }, { "signature_type": "Line", "deprecated": false, "source": "https://gitlab.freedesktop.org/xorg/xserver@26ef545b3502f61ca722a7a3373507e88ef64110", "signature_version": "v1", "target": { "file": "composite/compwindow.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "103254248831506398757703880392320180491", "339826436945346044112941835826143984965", "202660166280233479096158750827021754636", "213413363971156131415867680387795205297" ] }, "id": "CVE-2023-1393-2192cd90" } ]