Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50262

Опубликовано: 02 июн. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.

Отчет

Red Hat rates this issue as Moderate impact. In xorg-x11-server and xorg-x11-server-Xwayland, __glXDisp_ChangeDrawableAttributes() validates request size incorrectly, allowing a local X client to read bytes beyond the GLX request buffer—information disclosure. An out-of-bounds write path also exists but requires byte-swapped clients, which is disabled by default on Red Hat builds. Any local user who can connect to the X server display can trigger the read path. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tigervncAffected
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2026:2656622.06.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportxorg-x11-server-XwaylandFixedRHSA-2026:3679808.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2026:3608307.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2026:4647327.07.2026
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2026:2656217.06.2026
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2026:2670917.06.2026
Red Hat Enterprise Linux 8tigervncFixedRHSA-2026:2892324.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportxorg-x11-serverFixedRHSA-2026:3679208.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2485387xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes

EPSS

Процентиль: 3%
0.00132
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.

CVSS3: 5.5
nvd
около 2 месяцев назад

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.

CVSS3: 5.5
msrc
около 2 месяцев назад

Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes

CVSS3: 5.5
debian
около 2 месяцев назад

An out-of-bounds read flaw was found in the X.Org X server and Xwaylan ...

CVSS3: 5.5
github
около 2 месяцев назад

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.

EPSS

Процентиль: 3%
0.00132
Низкий

5.5 Medium

CVSS3