Impact
The vulnerability is a Heap Use‑After‑Free (CWE‑416) in the CommonMakeCurrent() function of the Xorg X11 Server and Xwayland. Local attackers with an X connection can supply a specially crafted GLX commit, causing the server to free memory that has later been reallocated. This flaw can corrupt the server’s heap, potentially allowing the attacker to execute arbitrary code in the server’s context or to crash client applications. It is a local vulnerability that requires access to an X display; exploitation would result in code execution on the host running the X server.
Affected Systems
Affected products are X.Org Xorg X11 Server and X.Org Xwayland. Vulnerable versions are before 21.2.24 for xorg-server and before 24.1.13 for xwayland. System administrators should ensure that these components are upgraded or otherwise fenced off. No other vendors or product lines are currently reported as affected by this CVE.
Risk and Exploitability
The CVSS score of 9.0 places this vulnerability in the critical severity range, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of assessment. It is not listed in the CISA KEV catalog, indicating no widespread exploitation reports yet. The likely attack vector is a local X connection; a local attacker with access to the X server can issue a crafted GLX commit to trigger the use‑after‑free. Successful exploitation could give the attacker local code execution or cause denial of service, making the risk significant for exposed systems.
OpenCVE Enrichment