PT-2026-56335 · X.Org Foundation · Xwayland+1

Published

2026-07-08

·

Updated

2026-07-15

·

CVE-2026-56000

CVSS v4.0

9.0

Critical

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions xorg-server versions prior to 21.2.24 xwayland versions prior to 24.1.13
Description Local attackers with an X connection can cause a Heap Use After Free, a condition where the system continues to use a memory address after it has been freed, potentially leading to crashes or arbitrary code execution. This occurs when providing a GLX commit to the X server because the CommonMakeCurrent() function points to memory that may have been reallocated.
Recommendations Update xorg-server to version 21.2.24 or later. Update xwayland to version 24.1.13 or later.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56000
OPENSUSE-SU-2026:11227-1
OPENSUSE-SU-2026:11244-1
OPENSUSE-SU-2026:21273-1
OPENSUSE-SU-2026:21283-1
SUSE-SU-2026:2786-1
SUSE-SU-2026:2787-1
SUSE-SU-2026:2788-1
SUSE-SU-2026:2789-1
SUSE-SU-2026:2791-1
ZDI-26-405

Affected Products

Xorg-Server
Xwayland