A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
{ "vanir_signatures": [ { "id": "CVE-2023-6377-463adbeb", "deprecated": false, "target": { "file": "dix/devices.c" }, "signature_type": "Line", "source": "https://gitlab.freedesktop.org/xorg/xserver@0c1a93d319558fe3ab2d94f51d174b4f93810afd", "digest": { "threshold": 0.9, "line_hashes": [ "252687557648165217032608315038685411166", "279832323036604406034105090042523305377", "174046644956456337769873931283469710560", "270428353536077042820062109791272058548", "5306838274834198535579455753337315613", "195921679156969440801451686002829746101", "151396372718625826199537758261571665405", "100013151932802024797321693179340322742" ] }, "signature_version": "v1" }, { "id": "CVE-2023-6377-bb1b42ed", "deprecated": false, "target": { "file": "Xi/exevents.c" }, "signature_type": "Line", "source": "https://gitlab.freedesktop.org/xorg/xserver@0c1a93d319558fe3ab2d94f51d174b4f93810afd", "digest": { "threshold": 0.9, "line_hashes": [ "62568919244241268195688987013639948482", "37362957716343082407980267540572748816", "16654370904255052517393063963994389453", "98929824099361305544272899779512004429", "241158125650748516153140667877312646975", "59866509609299917617511806777220449800", "284319984216367116843112254247973226776", "258475138249273764119512146929409733069", "44026588089028579398453030731936440344", "144310107527399638380947153528855736910" ] }, "signature_version": "v1" }, { "id": "CVE-2023-6377-c23d4ecb", "deprecated": false, "target": { "function": "DeepCopyPointerClasses", "file": "Xi/exevents.c" }, "signature_type": "Function", "source": "https://gitlab.freedesktop.org/xorg/xserver@0c1a93d319558fe3ab2d94f51d174b4f93810afd", "digest": { "length": 4368.0, "function_hash": "147771937936268740377913836205570780749" }, "signature_version": "v1" }, { "id": "CVE-2023-6377-e7c9187f", "deprecated": false, "target": { "function": "RecalculateMasterButtons", "file": "dix/devices.c" }, "signature_type": "Function", "source": "https://gitlab.freedesktop.org/xorg/xserver@0c1a93d319558fe3ab2d94f51d174b4f93810afd", "digest": { "length": 1557.0, "function_hash": "253571254798004793955492070510461122682" }, "signature_version": "v1" } ] }