Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33999

Опубликовано: 23 апр. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

Отчет

An Important integer underflow vulnerability exists in the X.Org X server's XKB compatibility map handling. This flaw allows an attacker with local or remote X11 server access to trigger a buffer read overrun, leading to memory-safety violations and potential denial of service. Red Hat Enterprise Linux systems utilizing the X.Org X server in graphical environments are affected.

Меры по смягчению последствий

To mitigate this issue, restrict access to the X11 server. For remote access, disable X11 forwarding in SSH configurations if not required. Edit /etc/ssh/sshd_config and set X11Forwarding no. After modifying the configuration, restart the sshd service using systemctl restart sshd. Disabling X11 forwarding may impact remote graphical applications.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2026:1135228.04.2026
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2026:1912519.05.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportxorg-x11-server-XwaylandFixedRHSA-2026:2056326.05.2026
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2026:2349604.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2026:2059026.05.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2026:2245602.06.2026
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2026:1165629.04.2026
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2026:1169229.04.2026
Red Hat Enterprise Linux 8tigervncFixedRHSA-2026:1341404.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2451106xorg: xwayland: X.Org X server: Denial of Service via integer underflow in XKB compatibility map handling

EPSS

Процентиль: 31%
0.0038
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

CVSS3: 7.8
nvd
3 месяца назад

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

msrc
3 месяца назад

Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling

CVSS3: 7.8
debian
3 месяца назад

A flaw was found in the X.Org X server. This integer underflow vulnera ...

CVSS3: 7.8
github
3 месяца назад

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

EPSS

Процентиль: 31%
0.0038
Низкий

7.8 High

CVSS3

Уязвимость CVE-2026-33999