CVE-2026-34001 Details
Description
A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.
A use-after-free vulnerability has been identified in the X.Org X server, specifically within the XSYNC fence triggering logic in the miSyncTriggerFence() function. This vulnerability allows an attacker with access to the X11 server to exploit the flaw without user interaction, leading to a server crash and potential memory corruption. Such exploitation could cause a denial-of-service or further compromise the system.
To mitigate this vulnerability, restrict access to the X11 server to trusted users and networks. If the X.Org X server is not needed, consider disabling or uninstalling it. In environments where the X server is essential, running X applications in a sandboxed environment can help reduce the attack surface.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-825 | Expired Pointer Dereference | redhat-SADP |
| CWE-825 | Expired Pointer Dereference | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
28 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | CVE Modified | [email protected] |
| Jun 5, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 4, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 28, 2026 | CVE Modified | [email protected] |
| Apr 28, 2026 | CVE Modified | [email protected] |
| Apr 28, 2026 | CVE Modified | [email protected] |
| Apr 27, 2026 | CVE Modified | [email protected] |
| Apr 23, 2026 | New CVE Received | [email protected] |