Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
CVSS Details
- CVSS 4.0 Base Score: 9 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xorg-serverUpgrade xwayland | Jul 9, 2026 | Jul 8, 2026 |
| Amazon_linux_2023 | — | Upgrade xorg-x11-server-XwaylandUpgrade xorg-x11-server-Xwayland-debuginfoUpgrade xorg-x11-server-Xwayland-develUpgrade xorg-x11-server-Xwayland-debugsource | Jul 21, 2026 | Jul 8, 2026 |
| Debian | — | Upgrade xorg-server | Sep 21, 2026 | Jul 8, 2026 |
| Freebsd | — | Upgrade xorg-serverUpgrade xwayland | Jul 9, 2026 | Jul 8, 2026 |
| Gentoo Linux | — | Upgrade x11-base/xwayland.Upgrade x11-base/xorg-server. | Aug 17, 2026 | Aug 17, 2026 |
| Redhat_linux | — | Upgrade xorg-x11-server-Xwayland-debuginfoUpgrade xorg-x11-server-Xwayland-develUpgrade xorg-x11-server-XwaylandUpgrade xorg-x11-server-Xwayland-debugsourceNo solution exists | Jul 14, 2026 | Jul 8, 2026 |
| Rocky_linux | — | Upgrade xorg-x11-server-XwaylandUpgrade xorg-x11-server-Xwayland-debuginfoUpgrade xorg-x11-server-Xwayland-develUpgrade xorg-x11-server-Xwayland-debugsource | Jul 16, 2026 | Jul 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub