« List of all CVEs

CVE-2023-43787

Libx11: integer overflow in xcreateimage() leading to a heap overflow

Published: 10/10/2023 Last updated: 11/6/2025 Reserved: 9/22/2023

A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.8 High CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Opam packages affected (2)

conf-libX11 raylib

Products affected (10)

Product Vendor Version
versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0)
Red Hat Enterprise Linux 8 Red Hat < 2021.1.24
Red Hat Enterprise Linux 9 Red Hat < unspecified
Red Hat Enterprise Linux 6 Red Hat < 2022.1.13
Red Hat Enterprise Linux 7 Red Hat < unspecified
15.1(1)SY
Red Hat Enterprise Linux 8 Red Hat 15.1(1)SY2
Red Hat Enterprise Linux 9 Red Hat 9205 LTE Modem
Red Hat Enterprise Linux 6 Red Hat <= <=9.1.11.0
Red Hat Enterprise Linux 7 Red Hat <= <=9.0.x.x

References (24)