CVE-2026-50259

EUVD-2026-34814
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
x.orgx_server
𝑥
< 21.1.23
x.orgxwayland
𝑥
< 24.1.12
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:24.1.9-4.el10_2.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:24.1.5-6.el10_0.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
0:1.20.4-35.el7_9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:21.1.3-20.el8_10.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:1.20.11-28.el8_10.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:1.15.0-10.el8_10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
0:1.20.10-5.el8_4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
0:1.20.10-5.el8_4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
0:1.20.11-8.el8_6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
0:21.1.3-2.el8_6.7 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
0:1.20.11-8.el8_6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
0:21.1.3-2.el8_6.7 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
0:1.20.11-19.el8_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
0:21.1.3-13.el8_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
0:1.20.11-19.el8_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
0:21.1.3-13.el8_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:24.1.9-4.el9_8.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:1.20.11-34.el9_8.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:1.15.0-7.el9_8.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:1.20.11-21.el9_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:21.1.3-10.el9_2.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
0:1.20.11-29.el9_4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
0:22.1.9-8.el9_4.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:1.20.11-34.el9_6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:23.2.7-6.el9_6.1 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
xorg-server
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
2:21.1.23-1
fixed
sid
2:21.1.23-1
fixed
trixie
2:21.1.16-1.3+deb13u3
fixed
trixie (security)
2:21.1.16-1.3+deb13u3
fixed
xwayland
bookworm
ignored
forky
2:24.1.12-1
fixed
sid
2:24.1.12-1
fixed
trixie
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
tigervnc
RHEL 8
0:1.15.0-10.el8_10
fixed
RHEL 9
0:1.15.0-7.el9_8.2
fixed
tigervnc-icons
RHEL 8
0:1.15.0-10.el8_10
fixed
RHEL 9
0:1.15.0-7.el9_8.2
fixed
tigervnc-license
RHEL 8
0:1.15.0-10.el8_10
fixed
RHEL 9
0:1.15.0-7.el9_8.2
fixed
tigervnc-selinux
RHEL 8
0:1.15.0-10.el8_10
fixed
RHEL 9
0:1.15.0-7.el9_8.2
fixed
tigervnc-server
RHEL 8
0:1.15.0-10.el8_10
fixed
RHEL 9
0:1.15.0-7.el9_8.2
fixed
tigervnc-server-minimal
RHEL 8
0:1.15.0-10.el8_10
fixed
RHEL 9
0:1.15.0-7.el9_8.2
fixed
tigervnc-server-module
RHEL 8
0:1.15.0-10.el8_10
fixed
RHEL 9
0:1.15.0-7.el9_8.2
fixed
xorg-x11-server-Xdmx
RHEL 8
0:1.20.11-28.el8_10.2
fixed
RHEL 8.4 AUS
0:1.20.10-5.el8_4
fixed
RHEL 8.6 AUS
0:1.20.11-8.el8_6
fixed
RHEL 8.8 E4S
0:1.20.11-19.el8_8
fixed
RHEL 8.8 TUS
0:1.20.11-19.el8_8
fixed
RHEL 9
0:1.20.11-34.el9_8.2
fixed
xorg-x11-server-Xephyr
RHEL 8
0:1.20.11-28.el8_10.2
fixed
RHEL 8.4 AUS
0:1.20.10-5.el8_4
fixed
RHEL 8.6 AUS
0:1.20.11-8.el8_6
fixed
RHEL 8.8 E4S
0:1.20.11-19.el8_8
fixed
RHEL 8.8 TUS
0:1.20.11-19.el8_8
fixed
RHEL 9
0:1.20.11-34.el9_8.2
fixed
xorg-x11-server-Xnest
RHEL 8
0:1.20.11-28.el8_10.2
fixed
RHEL 8.4 AUS
0:1.20.10-5.el8_4
fixed
RHEL 8.6 AUS
0:1.20.11-8.el8_6
fixed
RHEL 8.8 E4S
0:1.20.11-19.el8_8
fixed
RHEL 8.8 TUS
0:1.20.11-19.el8_8
fixed
RHEL 9
0:1.20.11-34.el9_8.2
fixed
xorg-x11-server-Xorg
RHEL 8
0:1.20.11-28.el8_10.2
fixed
RHEL 8.4 AUS
0:1.20.10-5.el8_4
fixed
RHEL 8.6 AUS
0:1.20.11-8.el8_6
fixed
RHEL 8.8 E4S
0:1.20.11-19.el8_8
fixed
RHEL 8.8 TUS
0:1.20.11-19.el8_8
fixed
RHEL 9
0:1.20.11-34.el9_8.2
fixed
xorg-x11-server-Xvfb
RHEL 8
0:1.20.11-28.el8_10.2
fixed
RHEL 8.4 AUS
0:1.20.10-5.el8_4
fixed
RHEL 8.6 AUS
0:1.20.11-8.el8_6
fixed
RHEL 8.8 E4S
0:1.20.11-19.el8_8
fixed
RHEL 8.8 TUS
0:1.20.11-19.el8_8
fixed
RHEL 9
0:1.20.11-34.el9_8.2
fixed
xorg-x11-server-Xwayland
RHEL 8.4 AUS
0:1.20.10-5.el8_4
fixed
RHEL 9
0:24.1.9-4.el9_8.2
fixed
xorg-x11-server-Xwayland-devel
RHEL 9
0:24.1.9-4.el9_8.2
fixed
xorg-x11-server-common
RHEL 8
0:1.20.11-28.el8_10.2
fixed
RHEL 8.4 AUS
0:1.20.10-5.el8_4
fixed
RHEL 8.6 AUS
0:1.20.11-8.el8_6
fixed
RHEL 8.8 E4S
0:1.20.11-19.el8_8
fixed
RHEL 8.8 TUS
0:1.20.11-19.el8_8
fixed
RHEL 9
0:1.20.11-34.el9_8.2
fixed
xorg-x11-server-devel
RHEL 8
0:1.20.11-28.el8_10.2
fixed
RHEL 9
0:1.20.11-34.el9_8.2
fixed
xorg-x11-server-source
RHEL 8
0:1.20.11-28.el8_10.2
fixed
RHEL 9
0:1.20.11-34.el9_8.2
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
tigervnc
Amazon Linux 2
0:1.8.0-24.amzn2.0.10
fixed
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-debuginfo
Amazon Linux 2
0:1.8.0-24.amzn2.0.10
fixed
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-debugsource
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-icons
Amazon Linux 2
0:1.8.0-24.amzn2.0.10
fixed
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-license
Amazon Linux 2
0:1.8.0-24.amzn2.0.10
fixed
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-selinux
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-server
Amazon Linux 2
0:1.8.0-24.amzn2.0.10
fixed
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-server-applet
Amazon Linux 2
0:1.8.0-24.amzn2.0.10
fixed
tigervnc-server-debuginfo
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-server-minimal
Amazon Linux 2
0:1.8.0-24.amzn2.0.10
fixed
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-server-minimal-debuginfo
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-server-module
Amazon Linux 2
0:1.8.0-24.amzn2.0.10
fixed
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
tigervnc-server-module-debuginfo
Amazon Linux 2023
0:1.14.1-3.amzn2023.0.6
fixed
xorg-x11-server-Xdmx
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
xorg-x11-server-Xephyr
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-Xephyr-debuginfo
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-Xnest
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-Xnest-debuginfo
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-Xorg
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-Xorg-debuginfo
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-Xvfb
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-Xvfb-debuginfo
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-Xwayland
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:24.1.3-1.amzn2023.0.5
fixed
xorg-x11-server-Xwayland-debuginfo
Amazon Linux 2023
0:24.1.3-1.amzn2023.0.5
fixed
xorg-x11-server-Xwayland-debugsource
Amazon Linux 2023
0:24.1.3-1.amzn2023.0.5
fixed
xorg-x11-server-Xwayland-devel
Amazon Linux 2023
0:24.1.3-1.amzn2023.0.5
fixed
xorg-x11-server-common
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-debuginfo
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-debugsource
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-devel
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
xorg-x11-server-source
Amazon Linux 2
0:1.20.4-22.amzn2.0.12
fixed
Amazon Linux 2023
0:21.1.13-5.amzn2023.0.10
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
xorg-x11-server-Xwayland
Azure Linux 3.0
0:24.1.12-1.azl3
fixed
References