X.org
X.org Xwayland: vulnerabilidades y CVE
X.org Xwayland tiene 30 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE30
Últimos 12 meses14
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-56000 | Crítica (9) | 0.31% | — | 8 jul 2026 | Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into… |
| CVE-2026-55999 | Alta (7.8) | 0.33% | — | 8 jul 2026 | Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. |
| CVE-2026-50264 | Alta (7.8) | 0.20% | — | 5 jun 2026 | An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger… |
| CVE-2026-50263 | Media (5.5) | 0.19% | — | 5 jun 2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information… |
| CVE-2026-50262 | Media (5.5) | 0.18% | — | 5 jun 2026 | An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer,… |
| CVE-2026-50261 | Alta (7.8) | 0.20% | — | 5 jun 2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client… |
| CVE-2026-50260 | Alta (7.8) | 0.20% | — | 5 jun 2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters… |
| CVE-2026-50259 | Alta (7.8) | 0.22% | — | 5 jun 2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes… |
| CVE-2026-50258 | Alta (7.8) | 0.22% | — | 5 jun 2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp… |
| CVE-2026-50257 | Alta (7.8) | 0.20% | — | 5 jun 2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to… |
| CVE-2026-50256 | Alta (7.8) | 0.21% | — | 5 jun 2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias… |
| CVE-2025-62230 | Alta (7.3) | 0.28% | — | 30 oct 2025 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a… |
| CVE-2025-62229 | Alta (7.3) | 0.51% | — | 30 oct 2025 | A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free… |
| CVE-2025-62231 | Alta (7.3) | 0.30% | — | 30 oct 2025 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted… |
| CVE-2025-26601 | Alta (7.8) | 0.39% | — | 25 feb 2025 | A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger()… |
| CVE-2025-26600 | Alta (7.8) | 0.39% | — | 25 feb 2025 | A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free. |
| CVE-2025-26599 | Alta (7.8) | 0.40% | — | 25 feb 2025 | An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc… |
| CVE-2025-26598 | Alta (7.8) | 0.40% | — | 25 feb 2025 | An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was… |
| CVE-2025-26597 | Alta (7.8) | 0.44% | — | 25 feb 2025 | A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later… |
| CVE-2025-26596 | Alta (7.8) | 0.44% | — | 25 feb 2025 | A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow. |
| CVE-2025-26595 | Alta (7.8) | 0.44% | — | 25 feb 2025 | A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the… |
| CVE-2025-26594 | Alta (7.8) | 0.39% | — | 25 feb 2025 | A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a… |
| CVE-2024-0229 | Alta (7.8) | 1.2% | — | 9 feb 2024 | An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash,… |
| CVE-2024-0409 | Alta (7.8) | 0.36% | — | 18 ene 2024 | A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that… |
| CVE-2024-0408 | Media (5.5) | 0.32% | — | 18 ene 2024 | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a… |
| CVE-2023-6816 | Crítica (9.8) | 2.1% | — | 18 ene 2024 | A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server… |
| CVE-2023-6478 | Alta (7.5) | 1.6% | — | 13 dic 2023 | A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information. |
| CVE-2023-6377 | Alta (7.8) | 1.6% | — | 13 dic 2023 | A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or… |
| CVE-2023-5380 | Media (4.7) | 0.71% | — | 25 oct 2023 | A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the… |
| CVE-2023-5367 | Alta (7.8) | 0.62% | — | 25 oct 2023 | A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in… |