CVE-2026-50264 Details
Description
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A vulnerability allowing out-of-bounds heap writes has been identified in the X.Org X server and Xwayland, specifically within the DRI2 buffer management functions DRIGetBuffers and DRIGetBuffersWithFormat. This flaw arises when a client requests multiple DRI2BufferBackLeft attachments along with one DRI2BufferFrontLeft, potentially leading to memory corruption. The vulnerability can be exploited to crash the server or escalate privileges if the X server is running as root.
Users can upgrade to X.Org X server version 21.1.23 or Xwayland version 24.1.12, both of which include the necessary fix. Instructions for upgrading can be found on the Red Hat Customer Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | redhat-SADP |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| x.org x server | < 21.1.23 |
CPE
Remediation
| |
| x.org xwayland | < 24.1.12 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
29 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | redhat-SADP |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 13, 2026 | CVE Modified | redhat-SADP |
| Jul 13, 2026 | CVE Modified | [email protected] |
| Jul 13, 2026 | CVE Modified | [email protected] |
| Jul 9, 2026 | CVE Modified | redhat-SADP |
| Jul 9, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | CVE Modified | redhat-SADP |
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | redhat-SADP |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 18, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 5, 2026 | New CVE Received | [email protected] |