Impact
A stack-based buffer overflow exists in the X.Org X server and Xwayland; the bug is triggered when a client changes key types to excessive shift levels, bypassing a check that limits the number of shift levels to XkbMaxShiftLevel. The overflow can crash the server or, if the X server runs as root, allow an attacker to execute arbitrary code and gain root privileges.
Affected Systems
Red Hat Enterprise Linux 6 through 10 are affected because the vulnerability resides in the X.Org X server component shipped with these distributions. Any system that runs the X server or Xwayland under these RHEL versions is potentially vulnerable.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker who can send malformed key type commands over the X protocol; this may be done locally or remotely if the X server exposes a network connection. If the X server is executed as root, the overflow can be leveraged for privilege escalation. The absence of an official workaround means patching is the only effective defense.
OpenCVE Enrichment
Debian DLA
Debian DSA