Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-50264

Опубликовано: 05 июн. 2026
Источник: debian
EPSS Низкий

Описание

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.23-1package
xwaylandfixed2:24.1.12-1package
xwaylandignoredtrixiepackage
xwaylandignoredbookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/06/02/1

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b7aa65cc3bb11b792ce2a3f511ba9b863acb11c8

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/339c279514326134b0878fc23ce6e9520440ce7f

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/4926348d826b7dc12d51d7e41bd9068aee5f90af (xorg-server-21.1.23)

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f0b8e6e1d969548c0625051d56a780e5df39de26 (xorg-server-21.1.23)

EPSS

Процентиль: 5%
0.00148
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 месяцев назад

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

CVSS3: 7.8
redhat
2 месяца назад

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

CVSS3: 7.8
nvd
около 2 месяцев назад

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

CVSS3: 7.8
github
около 2 месяцев назад

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

CVSS3: 5.5
fstec
3 месяца назад

Уязвимость модуля DRIGetBuffersWithFormat реализации протокола Wayland для X.Org XWaylan и реализации сервера X Window System X.Org Server, позволяющая нарушителю повысить свои привилегии и вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00148
Низкий