CVE-2026-50258 Details
Description
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A stack-based buffer overflow vulnerability has been identified in the X.Org X server and Xwayland. This issue arises because the X server has multiple stack buffers sized according to XkbMaxShiftLevel multiplied by XkbNumKbdGroups. However, the CheckKeyTypes() function fails to verify or restrict non-canonical key types to the maximum shift level. As a result, a client can manipulate key types to exceed the allowed shift levels, causing stack overflows. This vulnerability, which is a result of an incomplete fix for CVE-2025-26597, can lead to server crashes or privilege escalation if the X server is running as root.
Users can upgrade to X.Org X server version 21.1.23 or Xwayland version 24.1.12, both of which include the necessary fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | redhat-SADP |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| x.org x server | < 21.1.23 |
CPE
Remediation
| |
| x.org xwayland | < 24.1.12 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
31 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | redhat-SADP |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Jul 27, 2026 | CVE Modified | redhat-SADP |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 13, 2026 | CVE Modified | redhat-SADP |
| Jul 13, 2026 | CVE Modified | [email protected] |
| Jul 13, 2026 | CVE Modified | [email protected] |
| Jul 9, 2026 | CVE Modified | redhat-SADP |
| Jul 9, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | CVE Modified | redhat-SADP |
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | redhat-SADP |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 18, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 8, 2026 | Initial Analysis | [email protected] |
| Jun 5, 2026 | New CVE Received | [email protected] |