PT-2026-56335 · X.Org Foundation · Xwayland+1
Published
2026-07-08
·
Updated
2026-07-15
·
CVE-2026-56000
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
xorg-server versions prior to 21.2.24
xwayland versions prior to 24.1.13
Description
Local attackers with an X connection can cause a Heap Use After Free, a condition where the system continues to use a memory address after it has been freed, potentially leading to crashes or arbitrary code execution. This occurs when providing a GLX commit to the X server because the
CommonMakeCurrent() function points to memory that may have been reallocated.Recommendations
Update xorg-server to version 21.2.24 or later.
Update xwayland to version 24.1.13 or later.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xorg-Server
Xwayland