Description
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Published: 2026-06-05
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation
Action: Immediate Patch
AI Analysis

Impact

An out-of-bounds heap write occurs in the X.Org X server and Xwayland within the DRIGetBuffers/DRIGetBuffersWithFormat functions. A malicious client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger the flaw, potentially crashing the server or enabling privilege escalation if the X server is running as root. The weakness corresponds to the CWE-787 "Out-of-bounds Write" and directly undermines server integrity.

Affected Systems

Red Hat Enterprise Linux versions 6 through 10, which include the X.Org X server and Xwayland components. The affected packages are the default X server packages shipped with these RHEL releases.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The attack vector requires a client capable of connecting to the X server; if the X server is running with elevated privileges, an attacker can potentially achieve privilege escalation. Given the lack of publicly available exploits, the immediate threat is moderate until a proof‑of‑concept is released.

Generated by OpenCVE AI on June 5, 2026 at 12:21 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Apply the latest Red Hat update that includes the X.Org X server patch for this out‑of‑bounds write.
  • Restart or reboot the system so that the updated X server packages take effect.
  • Ensure that the X server service is not configured to run as root; set it to run as an unprivileged user or use systemd overrides to limit privileges.

Generated by OpenCVE AI on June 5, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4737-1 xorg-server security update
Debian DLA Debian DLA DLA-4738-1 xorg-server security update
Debian DSA Debian DSA DSA-6370-1 xorg-server security update
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:26562 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:26566 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:26590 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:26610 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:26709 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:28923 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:29844 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36083 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36085 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36086 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36087 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36632 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36633 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36634 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36768 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36791 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36792 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:36798 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:38502 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:38810 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:46377 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:46382 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:46385 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:46392 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:46456 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:46460 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:46473 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2026-50264 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2485389 cve-icon cve-icon
https://gitlab.freedesktop.org/xorg/xserver/-/commit/339c279514326134b0878fc23ce6e9520440ce7f cve-icon cve-icon cve-icon
https://lists.x.org/archives/xorg-announce/2026-June/003702.html cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-50264 cve-icon
https://redhat.atlassian.net/browse/PSIRTSUPT-16950 cve-icon cve-icon cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50264.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-50264 cve-icon
History

Mon, 27 Jul 2026 10:15:00 +0000


Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
References

Mon, 27 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
References

Mon, 27 Jul 2026 04:00:00 +0000


Mon, 13 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
References

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
References

Thu, 09 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux Eus
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_e4s:8.8::appstream
cpe:/a:redhat:rhel_tus:8.8::appstream
cpe:/o:redhat:enterprise_linux_eus:10.0
Vendors & Products Redhat enterprise Linux Eus
Redhat rhel Tus
References

Wed, 08 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_aus:8.4::appstream
cpe:/a:redhat:rhel_eus_long_life:8.4::appstream
References

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Aus
Redhat rhel Eus Long Life
CPEs cpe:/a:redhat:rhel_aus:8.6::appstream
cpe:/a:redhat:rhel_eus_long_life:8.6::appstream
Vendors & Products Redhat rhel Aus
Redhat rhel Eus Long Life
References

Wed, 08 Jul 2026 10:00:00 +0000


Tue, 07 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Els
Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_e4s:9.4::appstream
cpe:/a:redhat:rhel_eus:9.6::appstream
cpe:/a:redhat:rhel_eus:9.6::crb
cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel Els
Redhat rhel Eus
References

Tue, 07 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
CPEs cpe:/a:redhat:rhel_e4s:9.2::appstream
Vendors & Products Redhat rhel E4s
References

Thu, 25 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:9
References

Wed, 24 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8
References

Mon, 22 Jun 2026 08:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:10.2
References

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::crb
cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/a:redhat:enterprise_linux:9::crb
References

Wed, 17 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::appstream
References

Tue, 16 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared X.org x Server
X.org xwayland
CPEs cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*
cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products X.org x Server
X.org xwayland

Sun, 07 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared X.org
X.org xorg-server
Vendors & Products X.org
X.org xorg-server

Fri, 05 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 05 Jun 2026 11:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Title Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformat
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-787
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux Enterprise Linux Eus Rhel Aus Rhel E4s Rhel Els Rhel Eus Rhel Eus Long Life Rhel Tus
X.org X Server Xorg-server Xwayland
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-28T11:46:22.997Z

Reserved: 2026-06-04T14:55:24.012Z

Link: CVE-2026-50264

cve-icon Vulnrichment

Updated: 2026-07-27T12:05:43.283Z

cve-icon NVD

Status : Modified

Published: 2026-06-05T12:16:40.080

Modified: 2026-07-27T13:18:19.647

Link: CVE-2026-50264

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-50264 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T11:17:06Z

Weaknesses