A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3686-1 xorg-server security update
Debian DSA Debian DSA DSA-5576-1 xorg-server security update
EUVD EUVD EUVD-2023-58711 A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
Ubuntu USN Ubuntu USN USN-6555-1 X.Org X Server vulnerabilities
Ubuntu USN Ubuntu USN USN-6555-2 X.Org X Server vulnerabilities
Ubuntu USN Ubuntu USN USN-6587-5 X.Org X Server vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References
Link Providers
http://www.openwall.com/lists/oss-security/2023/12/13/1 cve-icon
https://access.redhat.com/errata/RHSA-2023:7886 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0006 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0009 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0010 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0014 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0015 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0016 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0017 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0018 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0020 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:2169 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:2170 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:2995 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:2996 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2025:12751 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2023-6478 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2253298 cve-icon cve-icon
https://gitlab.freedesktop.org/xorg/xserver/-/commit/14f480010a93ff962fef66a16412fafff81ad632 cve-icon cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2023/12/msg00008.html cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6R63Z6GIWM3YUNZRCGFODUXLW3GY2HD6/ cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7PP47YXKM5ETLCYEF6473R3VFCJ6QT2S/ cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFHV5KCQ2SVOD4QMCPZ5HC6YL44L7YJD/ cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LJDFWDB7EQVZA45XDP7L5WRSRWS6RVRR/ cve-icon
https://lists.x.org/archives/xorg-announce/2023-December/003435.html cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2023-6478 cve-icon
https://security.gentoo.org/glsa/202401-30 cve-icon
https://security.netapp.com/advisory/ntap-20240125-0003/ cve-icon
https://www.cve.org/CVERecord?id=CVE-2023-6478 cve-icon
https://www.debian.org/security/2023/dsa-5576 cve-icon
History

Mon, 04 Aug 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Els
CPEs cpe:/o:redhat:rhel_els:6
Vendors & Products Redhat rhel Els
References

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01017}

epss

{'score': 0.00875}


Fri, 22 Nov 2024 12:00:00 +0000


Mon, 16 Sep 2024 16:30:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-08-04T21:03:38.761Z

Reserved: 2023-12-04T06:40:47.239Z

Link: CVE-2023-6478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-13T07:15:31.213

Modified: 2025-08-04T21:15:27.830

Link: CVE-2023-6478

cve-icon Redhat

Severity : Important

Publid Date: 2023-12-13T00:00:00Z

Links: CVE-2023-6478 - Bugzilla

cve-icon OpenCVE Enrichment

No data.