Stack-Based Buffer Overflow in X.Org X Server and Xwayland
CVE-2026-50258

7.8HIGH

What is CVE-2026-50258?

A stack-based buffer overflow vulnerability exists in the X.Org X server and Xwayland, where the CheckKeyTypes() function fails to properly verify or restrict non-canonical key types according to their defined limits. This flaw allows attackers to manipulate key types to exceed acceptable shift levels, leading to potential stack overflow scenarios. The issue stems from an incomplete fix of a previous vulnerability and could result in server crashes or privilege escalation, particularly if the X server is running with root privileges.

Affected Version(s)

Red Hat Enterprise Linux 10 0:24.1.9-4.el10_2.2

Red Hat Enterprise Linux 10.0 Extended Update Support 0:24.1.5-6.el10_0.1

Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.20.4-35.el7_9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.
.