Описание
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
Отчет
Red Hat rates this issue as Moderate impact. In xorg-x11-server and xorg-x11-server-Xwayland, __glXDisp_ChangeDrawableAttributes() validates request size incorrectly, allowing a local X client to read bytes beyond the GLX request buffer—information disclosure. An out-of-bounds write path also exists but requires byte-swapped clients, which is disabled by default on Red Hat builds. Any local user who can connect to the X server display can trigger the read path. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | tigervnc | Affected | ||
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | ||
| Red Hat Enterprise Linux 10 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26566 | 22.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | xorg-x11-server-Xwayland | Fixed | RHSA-2026:36798 | 08.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | xorg-x11-server | Fixed | RHSA-2026:36083 | 07.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | tigervnc | Fixed | RHSA-2026:46473 | 27.07.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26562 | 17.06.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server | Fixed | RHSA-2026:26709 | 17.06.2026 |
| Red Hat Enterprise Linux 8 | tigervnc | Fixed | RHSA-2026:28923 | 24.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | xorg-x11-server | Fixed | RHSA-2026:36792 | 08.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes
An out-of-bounds read flaw was found in the X.Org X server and Xwaylan ...
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
EPSS
5.5 Medium
CVSS3