Impact
An out-of-bounds heap write occurs in the X.Org X server and Xwayland within the DRIGetBuffers/DRIGetBuffersWithFormat functions. A malicious client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger the flaw, potentially crashing the server or enabling privilege escalation if the X server is running as root. The weakness corresponds to the CWE-787 "Out-of-bounds Write" and directly undermines server integrity.
Affected Systems
Red Hat Enterprise Linux versions 6 through 10, which include the X.Org X server and Xwayland components. The affected packages are the default X server packages shipped with these RHEL releases.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The attack vector requires a client capable of connecting to the X server; if the X server is running with elevated privileges, an attacker can potentially achieve privilege escalation. Given the lack of publicly available exploits, the immediate threat is moderate until a proof‑of‑concept is released.
OpenCVE Enrichment