Описание
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Отчет
Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, a local X client can trigger a use-after-free function pointer call in miSyncDestroyFence() by setting up a fence trigger on one connection and destroying the fence from a second connection. Any local user who can connect to the X server display can attempt exploitation. This may crash the display server or, where the X server runs with elevated privileges, could contribute to local privilege escalation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | tigervnc | Affected | ||
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | ||
| Red Hat Enterprise Linux 7 | tigervnc | Affected | ||
| Red Hat Enterprise Linux 10 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26566 | 22.06.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | xorg-x11-server | Fixed | RHSA-2026:36083 | 07.07.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26562 | 17.06.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server | Fixed | RHSA-2026:26709 | 17.06.2026 |
| Red Hat Enterprise Linux 8 | tigervnc | Fixed | RHSA-2026:28923 | 24.06.2026 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26590 | 17.06.2026 |
| Red Hat Enterprise Linux 9 | xorg-x11-server | Fixed | RHSA-2026:26610 | 17.06.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()
A use-after-free flaw was found in the X.Org X server and Xwayland in ...
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
EPSS
7.8 High
CVSS3