Out-of-Bounds Read Vulnerability in X.Org X Server and Xwayland
CVE-2026-50262
Key Information:
What is CVE-2026-50262?
An out-of-bounds read flaw exists in the X.Org X server and Xwayland functions, particularly in __glXDisp_ChangeDrawableAttributes(). This vulnerability results from improper size validation checks that allow a client-controlled number of bytes to be read, potentially exceeding the request buffer limit. This condition can lead to inadvertent information disclosure. Although a write path has been identified, it is typically disabled by default and requires byte-swapped clients to be exploited.
Affected Version(s)
Red Hat Enterprise Linux 10 0:24.1.9-4.el10_2.2
Red Hat Enterprise Linux 10.0 Extended Update Support 0:24.1.5-6.el10_0.1
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION 0:1.1.0-25.el6_10.18
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved