A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
| Software | From | Fixed in |
|---|---|---|
| redhat / enterprise_linux_eus | 9.2 | 9.2.x |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |
| debian / debian_linux | 12.0 | 12.0.x |
| x.org / x_server | - | 21.1.10 |
| x.org / xwayland | - | 23.2.3 |