Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49pm-cgmh-hw25

Опубликовано: 30 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

Ссылки

EPSS

Процентиль: 3%
0.00015
Низкий

7.3 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.3
ubuntu
5 месяцев назад

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

CVSS3: 7.3
redhat
5 месяцев назад

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

CVSS3: 7.3
nvd
5 месяцев назад

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

CVSS3: 7.8
msrc
5 месяцев назад

Xorg: xmayland: use-after-free in xpresentnotify structure creation

CVSS3: 7.3
debian
5 месяцев назад

A flaw was found in the X.Org X server and Xwayland when processing X1 ...

EPSS

Процентиль: 3%
0.00015
Низкий

7.3 High

CVSS3

Дефекты

CWE-416