Description: A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used. Broken commit info: Bugfix commit info: https://access.redhat.com/security/cve/CVE-2023-6816 https://gitlab.freedesktop.org/xorg/xserver/-/commit/b5cb27032d3e486ba84a491e1420e85171c4c0a3 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EJBMCWQ54R6ZL3MYU2D2JBW6JMZL7BQW/ https://access.redhat.com/errata/RHSA-2024:0320 http://www.openwall.com/lists/oss-security/2024/01/18/1 https://gitlab.freedesktop.org/xorg/xserver/-/commit/4e78bc3a6e593f70aa5306b314edbec03d2f9081 https://lists.debian.org/debian-lts-announce/2024/01/msg00016.html https://bugzilla.redhat.com/show_bug.cgi?id=2257691 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5J4H7CH565ALSZZYKOJFYDA5KFLG6NUK/