Description
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Published: 2026-06-05
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw was discovered in the X.Org X Server and Xwayland implementation of freecounter(). An attacker can create multiple SyncCounters from one client and then trigger their deletion via a second client connection, causing an access to freed memory. This triggers either a crash of the X server or, if the server is running with elevated privileges, a privilege‑escalation opportunity for the attacker.

Affected Systems

Red Hat Enterprise Linux 6, 7, 8, 9 and 10 running the bundled X.Org X Server and Xwayland components are affected by this vulnerability.

Risk and Exploitability

The flaw carries a CVSS score of 7.8, indicating a moderate‑to‑high level of risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation would typically require a local or networked client able to interact with the X server, and could lead to denial of service or elevation of privilege when the X server runs as root.

Generated by OpenCVE AI on June 5, 2026 at 12:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Red Hat security update that patches the X.Org X Server and Xwayland components for CVE‑2026‑50260.
  • If Xwayland usage is not required, disable or remove it to reduce the attack surface.
  • Configure the X server to run under a non‑privileged user account or use per‑user X server instances to mitigate the privilege escalation risk.

Generated by OpenCVE AI on June 5, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6370-1 xorg-server security update
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:26562 cve-icon
https://access.redhat.com/errata/RHSA-2026:26566 cve-icon
https://access.redhat.com/errata/RHSA-2026:26590 cve-icon
https://access.redhat.com/errata/RHSA-2026:26610 cve-icon
https://access.redhat.com/errata/RHSA-2026:26709 cve-icon
https://access.redhat.com/errata/RHSA-2026:28923 cve-icon
https://access.redhat.com/errata/RHSA-2026:29844 cve-icon
https://access.redhat.com/errata/RHSA-2026:36083 cve-icon
https://access.redhat.com/errata/RHSA-2026:36085 cve-icon
https://access.redhat.com/errata/RHSA-2026:36086 cve-icon
https://access.redhat.com/errata/RHSA-2026:36087 cve-icon
https://access.redhat.com/errata/RHSA-2026:36632 cve-icon
https://access.redhat.com/errata/RHSA-2026:36633 cve-icon
https://access.redhat.com/errata/RHSA-2026:36634 cve-icon
https://access.redhat.com/errata/RHSA-2026:36768 cve-icon
https://access.redhat.com/errata/RHSA-2026:36791 cve-icon
https://access.redhat.com/errata/RHSA-2026:36792 cve-icon
https://access.redhat.com/errata/RHSA-2026:36798 cve-icon
https://access.redhat.com/errata/RHSA-2026:38502 cve-icon
https://access.redhat.com/errata/RHSA-2026:38810 cve-icon
https://access.redhat.com/errata/RHSA-2026:46377 cve-icon
https://access.redhat.com/errata/RHSA-2026:46382 cve-icon
https://access.redhat.com/errata/RHSA-2026:46385 cve-icon
https://access.redhat.com/errata/RHSA-2026:46392 cve-icon
https://access.redhat.com/errata/RHSA-2026:46456 cve-icon
https://access.redhat.com/errata/RHSA-2026:46460 cve-icon
https://access.redhat.com/errata/RHSA-2026:46473 cve-icon
https://access.redhat.com/errata/RHSA-2026:49519 cve-icon
https://access.redhat.com/security/cve/CVE-2026-50260 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2485385 cve-icon cve-icon
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b cve-icon cve-icon cve-icon
https://lists.x.org/archives/xorg-announce/2026-June/003702.html cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-50260 cve-icon
https://redhat.atlassian.net/browse/PSIRTSUPT-16950 cve-icon cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-50260 cve-icon
History

Tue, 04 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:rhel_els:6
References

Mon, 27 Jul 2026 10:15:00 +0000


Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
References

Mon, 27 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
References

Mon, 27 Jul 2026 04:00:00 +0000


Mon, 13 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
References

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
References

Thu, 09 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux Eus
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_e4s:8.8::appstream
cpe:/a:redhat:rhel_tus:8.8::appstream
cpe:/o:redhat:enterprise_linux_eus:10.0
Vendors & Products Redhat enterprise Linux Eus
Redhat rhel Tus
References

Wed, 08 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_aus:8.4::appstream
cpe:/a:redhat:rhel_eus_long_life:8.4::appstream
References

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Aus
Redhat rhel Eus Long Life
CPEs cpe:/a:redhat:rhel_aus:8.6::appstream
cpe:/a:redhat:rhel_eus_long_life:8.6::appstream
Vendors & Products Redhat rhel Aus
Redhat rhel Eus Long Life
References

Wed, 08 Jul 2026 10:00:00 +0000


Tue, 07 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Els
Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_e4s:9.4::appstream
cpe:/a:redhat:rhel_eus:9.6::appstream
cpe:/a:redhat:rhel_eus:9.6::crb
cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel Els
Redhat rhel Eus
References

Tue, 07 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
CPEs cpe:/a:redhat:rhel_e4s:9.2::appstream
Vendors & Products Redhat rhel E4s
References

Thu, 25 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:9
References

Wed, 24 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8
References

Mon, 22 Jun 2026 08:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:10.2
References

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::crb
cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/a:redhat:enterprise_linux:9::crb
References

Wed, 17 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::appstream
References

Thu, 11 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared X.org x Server
X.org xwayland
CPEs cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*
cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products X.org x Server
X.org xwayland

Sun, 07 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared X.org
X.org xorg-server
Vendors & Products X.org
X.org xorg-server

Fri, 05 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 05 Jun 2026 11:45:00 +0000

Type Values Removed Values Added
Description A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Title Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-416
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux Enterprise Linux Eus Rhel Aus Rhel E4s Rhel Els Rhel Eus Rhel Eus Long Life Rhel Tus
X.org X Server Xorg-server Xwayland
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-04T23:22:50.028Z

Reserved: 2026-06-04T14:55:24.011Z

Link: CVE-2026-50260

cve-icon Vulnrichment

Updated: 2026-07-27T12:05:30.547Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-05T12:16:39.430

Modified: 2026-06-11T18:36:20.720

Link: CVE-2026-50260

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-50260 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T11:17:09Z

Weaknesses