Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34001

Опубликовано: 23 апр. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

EPSS

Процентиль: 18%
0.00264
Низкий

7.8 High

CVSS3

Дефекты

CWE-825
CWE-825

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

CVSS3: 7.8
redhat
3 месяца назад

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

msrc
3 месяца назад

Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption

CVSS3: 7.8
debian
3 месяца назад

A flaw was found in the X.Org X server. This use-after-free vulnerabil ...

CVSS3: 7.8
github
3 месяца назад

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

EPSS

Процентиль: 18%
0.00264
Низкий

7.8 High

CVSS3

Дефекты

CWE-825
CWE-825