Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34001

Опубликовано: 23 апр. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.22-1package
xorg-serverfixed2:21.1.16-1.3+deb13u2trixiepackage
xorg-serverfixed2:21.1.7-3+deb12u12bookwormpackage
xorg-serverpostponedbullseyepackage
xwaylandfixed2:24.1.10-1package
xwaylandignoredtrixiepackage
xwaylandignoredbookwormpackage

Примечания

  • https://lists.x.org/archives/xorg-announce/2026-April/003677.html

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f19ab94ba9c891d801231654267556dc7f32b5e0

EPSS

Процентиль: 18%
0.00264
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

CVSS3: 7.8
redhat
3 месяца назад

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

CVSS3: 7.8
nvd
3 месяца назад

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

msrc
3 месяца назад

Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption

CVSS3: 7.8
github
3 месяца назад

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

EPSS

Процентиль: 18%
0.00264
Низкий