Skip to content
Threat Feed
medium advisory

X.Org X11 Denial of Service Vulnerability

A vulnerability in X.Org X11 (CVE-2023-6478) allows a remote, authenticated attacker to trigger a Denial of Service condition through resource exhaustion.

CVE search metadata

CVE search record: CVE-2023-6478. Severity: high. CVSS: 7.6. EPSS: 1.63%. KEV: no. Product: X.Org X11. Brief: X.Org X11 Denial of Service Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-08-xorg-dos/

The X.Org Foundation has identified a security vulnerability in X.Org X11, tracked as CVE-2023-6478. The flaw allows a remote, authenticated attacker to induce a Denial of Service (DoS) state on a target system. By leveraging authenticated access, an attacker can exploit internal handling mechanisms within the X11 server to cause resource exhaustion or service disruption. This vulnerability poses a risk to environments where untrusted users possess authenticated access to the X11 display environment. Defenders should prioritize updating X.Org X11 packages to versions that incorporate the upstream patches for this issue.

Impact

Successful exploitation results in the interruption of the X11 server, rendering the graphical display interface unavailable to the user. This impacts systems running X.Org X11 across Linux and macOS distributions, potentially affecting workstation stability or availability in multi-user environments.

Recommendation

  • Patch CVE-2023-6478 by upgrading the X.Org X11 server packages to the vendor-provided secure versions.
  • Audit user permissions for X11 server access to ensure only authorized entities can establish authenticated sessions.

Mitigations

Patch CVE-2023-6478

medium_term IT Operations

CVE-2023-6478