Stack-Based Buffer Overflow in X.Org X Server and Xwayland
CVE-2026-50258
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-50258?
A stack-based buffer overflow vulnerability exists in the X.Org X server and Xwayland, where the CheckKeyTypes() function fails to properly verify or restrict non-canonical key types according to their defined limits. This flaw allows attackers to manipulate key types to exceed acceptable shift levels, leading to potential stack overflow scenarios. The issue stems from an incomplete fix of a previous vulnerability and could result in server crashes or privilege escalation, particularly if the X server is running with root privileges.
Affected Version(s)
Red Hat Enterprise Linux 10 0:24.1.9-4.el10_2.2
Red Hat Enterprise Linux 10.0 Extended Update Support 0:24.1.5-6.el10_0.1
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.20.4-35.el7_9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved