Описание
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Отчет
Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, a local X client that requests multiple DRI2BufferBackLeft attachments together with DRI2BufferFrontLeft can trigger an out-of-bounds heap write in DRIGetBuffers/DRIGetBuffersWithFormat. Any local user with X display access can trigger this. It may crash the server or, where the X server runs with elevated privileges, could contribute to local privilege escalation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | tigervnc | Affected | ||
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | ||
| Red Hat Enterprise Linux 10 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26566 | 22.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | xorg-x11-server-Xwayland | Fixed | RHSA-2026:36798 | 08.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | xorg-x11-server | Fixed | RHSA-2026:36083 | 07.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | tigervnc | Fixed | RHSA-2026:46473 | 27.07.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26562 | 17.06.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server | Fixed | RHSA-2026:26709 | 17.06.2026 |
| Red Hat Enterprise Linux 8 | tigervnc | Fixed | RHSA-2026:28923 | 24.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | xorg-x11-server | Fixed | RHSA-2026:36792 | 08.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
An out-of-bounds write flaw was found in the X.Org X server and Xwayla ...
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Уязвимость модуля DRIGetBuffersWithFormat реализации протокола Wayland для X.Org XWaylan и реализации сервера X Window System X.Org Server, позволяющая нарушителю повысить свои привилегии и вызвать отказ в обслуживании
EPSS
7.8 High
CVSS3