CVE-2023-5574
HIGHCVSS v3.1: 7.0 · EPSS: 0.0054 (41.0 percentile)
Source data as of:
At a glance
- Severity
- HIGH
- CVSS
- 7.0 v3.1 · NVD
- EPSS
- 0.0054 (41.0 percentile) · FIRST.org
- CISA KEV
- No
- Type
- Use After Free · NVD CWE
- Attack conditions (CVSS vector)
- No user interaction · Source: NVD Vector
- Affected vendors
- redhat, x.org
- Published
- 2023-10-25 · Modified: 2026-06-23
- References
- Jump to references (5)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.
- Distro https://access.redhat.com/errata/RHSA-2024:2298
- Distro https://access.redhat.com/security/cve/CVE-2023-5574
- Distro https://bugzilla.redhat.com/show_bug.cgi?id=2244735
- Reference https://lists.x.org/archives/xorg-announce/2023-October/003430.html
- Distro https://security.netapp.com/advisory/ntap-20231130-0004/