Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33999

Опубликовано: 23 апр. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.22-1package
xorg-serverfixed2:21.1.16-1.3+deb13u2trixiepackage
xorg-serverfixed2:21.1.7-3+deb12u12bookwormpackage
xorg-serverpostponedbullseyepackage
xwaylandfixed2:24.1.10-1package
xwaylandignoredtrixiepackage
xwaylandignoredbookwormpackage

Примечания

  • https://lists.x.org/archives/xorg-announce/2026-April/003677.html

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b024ae1749ee58c6fbf863b9a1f5dc440fee2e1b

EPSS

Процентиль: 31%
0.0038
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

CVSS3: 7.8
redhat
3 месяца назад

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

CVSS3: 7.8
nvd
3 месяца назад

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

msrc
3 месяца назад

Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling

CVSS3: 7.8
github
3 месяца назад

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

EPSS

Процентиль: 31%
0.0038
Низкий