CVE-2023-5574
TigerVNC vulnerability analysis and mitigation

Overview

A use-after-free vulnerability (CVE-2023-5574) was discovered in xorg-x11-server-Xvfb, specifically affecting systems with a legacy multi-screen setup using multiple protocol screens (Zaphod mode). The vulnerability was discovered in October 2023 and affects X.Org X server versions from 1.13.0 onwards (Xorg Announce). The issue received a CVSS v3.1 base score of 7.0 (HIGH) (NVD).

Technical details

The vulnerability occurs due to improper handling of screen cleanup in the fb module. The module hardcoded the cleanup path for the screen pixmap instead of calling into the next layer of the stack. While a patch in server 1.13 attempted to fix a minor memory leak, it failed to remove all references to the freed pixmap, resulting in a use-after-free condition during screen cleanup in a lower module. The issue is triggered when the pointer is warped from screen 1 to screen 0 and specifically requires a multi-screen setup with Zaphod mode configuration (Xorg Announce).

Impact

When successfully exploited, this vulnerability could lead to privilege escalation or denial of service. The impact is particularly concerning for systems using the specific legacy configuration of Xvfb with multiple protocol screens. The vulnerability can be triggered during shutdown or reset of the Xvfb server (Red Hat).

Mitigation and workarounds

As of the initial disclosure, no complete fix was available due to issues with the proposed fixes. The patches had to be dropped just before disclosure because they exposed issues in other, more commonly used components. The fixes are being tracked through a merge request at the X.Org GitLab repository (Bugzilla).

Additional resources


SourceThis report was generated using AI

Related TigerVNC vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-49180HIGH7.8
  • TigerVNCTigerVNC
  • xorg-x11-server-doc
NoYesJun 17, 2025
CVE-2025-62230HIGH7.3
  • TigerVNCTigerVNC
  • tigervnc-server
NoYesOct 30, 2025
CVE-2025-62229HIGH7.3
  • TigerVNCTigerVNC
  • xorg-x11-server-Xorg-debuginfo
NoYesOct 30, 2025
CVE-2025-62231HIGH7.3
  • TigerVNCTigerVNC
  • xorg-x11-server-Xnest
NoYesOct 30, 2025
ELSA-2025-20958HIGHN/A
  • TigerVNCTigerVNC
  • tigervnc-icons
NoYesNov 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management