Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56000

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

A flaw was found in the X.org X11 server, specifically within the GLX (OpenGL Extension to the X Window System) dispatch layer. A remote attacker can exploit this vulnerability by sending a series of crafted X11 requests. This can lead to a use-after-free condition, where the server attempts to write data to memory that has already been released. The primary consequence of this memory corruption is a denial of service, potentially causing the X server to crash.

Отчет

An Important use-after-free vulnerability in the X.org X11 server's GLX dispatch layer allows a remote, unauthenticated attacker to trigger a denial of service. By sending a sequence of crafted X11 requests, an attacker can cause the X server to crash, impacting the availability of systems with a running graphical environment. This is considered Important due to the remote attack vector and the potential for unauthenticated denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverNot affected
Red Hat Enterprise Linux 7xorg-x11-serverNot affected
Red Hat Enterprise Linux 8xorg-x11-serverAffected
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandAffected
Red Hat Enterprise Linux 9xorg-x11-serverAffected
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2026:3848913.07.2026
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandFixedRHSA-2026:3849013.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2496193X.org: xorg-x11-server: GLX contextTags Use-After-Free in CommonMakeCurrent()

EPSS

Процентиль: 13%
0.00222
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
23 дня назад

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

CVSS3: 7.8
nvd
23 дня назад

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

msrc
23 дня назад

xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()

CVSS3: 7.8
debian
23 дня назад

Local attackers with a X connection able to provide GLX commit to the ...

CVSS3: 7.8
github
23 дня назад

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

EPSS

Процентиль: 13%
0.00222
Низкий

6.5 Medium

CVSS3