Описание
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
A flaw was found in the X.org X11 server, specifically within the GLX (OpenGL Extension to the X Window System) dispatch layer. A remote attacker can exploit this vulnerability by sending a series of crafted X11 requests. This can lead to a use-after-free condition, where the server attempts to write data to memory that has already been released. The primary consequence of this memory corruption is a denial of service, potentially causing the X server to crash.
Отчет
An Important use-after-free vulnerability in the X.org X11 server's GLX dispatch layer allows a remote, unauthenticated attacker to trigger a denial of service. By sending a sequence of crafted X11 requests, an attacker can cause the X server to crash, impacting the availability of systems with a running graphical environment. This is considered Important due to the remote attack vector and the potential for unauthenticated denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | xorg-x11-server | Not affected | ||
| Red Hat Enterprise Linux 7 | xorg-x11-server | Not affected | ||
| Red Hat Enterprise Linux 8 | xorg-x11-server | Affected | ||
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Affected | ||
| Red Hat Enterprise Linux 9 | xorg-x11-server | Affected | ||
| Red Hat Enterprise Linux 10 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:38489 | 13.07.2026 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:38490 | 13.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
Local attackers with a X connection able to provide GLX commit to the ...
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
EPSS
6.5 Medium
CVSS3