CVE-2026-56000
EUVD-2026-4220208.07.2026, 09:16
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| x.org | x_server | 𝑥 < 21.2.24 |
| x.org | xwayland | 𝑥 < 24.1.13 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg |
| ||||||||||||||||
| xorg-server |
| ||||||||||||||||
| xwayland |
| ||||||||||||||||
| xorg-server-hwe-16.04 |
| ||||||||||||||||
| xorg-server-hwe-18.04 |
| ||||||||||||||||
| xorg-hwe-16.04 |
| ||||||||||||||||
| xorg-hwe-18.04 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-x11-server |
| ||||||||||||
| xorg-x11-server-Xvfb |
| ||||||||||||
| xorg-x11-server-extra |
| ||||||||||||
| xorg-x11-server-sdk |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| xorg-x11-server-Xwayland |
| ||
| xorg-x11-server-Xwayland-debuginfo |
| ||
| xorg-x11-server-Xwayland-debugsource |
| ||
| xorg-x11-server-Xwayland-devel |
|
Azure Linux Releases
Common Weakness Enumeration