Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
CVSS Details
- CVSS 4.0 Base Score: 9 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xwaylandUpgrade xorg-server | Jul 9, 2026 | Jul 8, 2026 |
| Amazon_linux_2023 | — | Upgrade xorg-x11-server-Xwayland-debugsourceUpgrade xorg-x11-server-XwaylandUpgrade xorg-x11-server-Xwayland-debuginfoUpgrade xorg-x11-server-Xwayland-devel | Jul 21, 2026 | Jul 8, 2026 |
| Debian | — | Upgrade xorg-server | Sep 21, 2026 | Jul 8, 2026 |
| Freebsd | — | Upgrade xorg-serverUpgrade xwayland | Jul 9, 2026 | Jul 8, 2026 |
| Gentoo Linux | — | Upgrade x11-base/xorg-server.Upgrade x11-base/xwayland. | Aug 17, 2026 | Aug 17, 2026 |
| Redhat_linux | — | Upgrade xorg-x11-server-XwaylandUpgrade xorg-x11-server-Xwayland-develUpgrade xorg-x11-server-Xwayland-debugsourceNo solution existsUpgrade xorg-x11-server-Xwayland-debuginfo | Jul 14, 2026 | Jul 8, 2026 |
| Rocky_linux | — | Upgrade xorg-x11-server-Xwayland-debugsourceUpgrade xorg-x11-server-Xwayland-debuginfoUpgrade xorg-x11-server-Xwayland-develUpgrade xorg-x11-server-Xwayland | Jul 16, 2026 | Jul 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub