Description
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
Published: 2026-07-08
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Heap Use‑After‑Free (CWE‑416) in the CommonMakeCurrent() function of the Xorg X11 Server and Xwayland. Local attackers with an X connection can supply a specially crafted GLX commit, causing the server to free memory that has later been reallocated. This flaw can corrupt the server’s heap, potentially allowing the attacker to execute arbitrary code in the server’s context or to crash client applications. It is a local vulnerability that requires access to an X display; exploitation would result in code execution on the host running the X server.

Affected Systems

Affected products are X.Org Xorg X11 Server and X.Org Xwayland. Vulnerable versions are before 21.2.24 for xorg-server and before 24.1.13 for xwayland. System administrators should ensure that these components are upgraded or otherwise fenced off. No other vendors or product lines are currently reported as affected by this CVE.

Risk and Exploitability

The CVSS score of 9.0 places this vulnerability in the critical severity range, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of assessment. It is not listed in the CISA KEV catalog, indicating no widespread exploitation reports yet. The likely attack vector is a local X connection; a local attacker with access to the X server can issue a crafted GLX commit to trigger the use‑after‑free. Successful exploitation could give the attacker local code execution or cause denial of service, making the risk significant for exposed systems.

Generated by OpenCVE AI on July 29, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade xorg‑x11‑server to the latest stable release.
  • Upgrade xwayland to the latest stable release.
  • If updates are not yet available, restrict X server access to trusted users and limit GLX contextTags usage in the server configuration.

Generated by OpenCVE AI on July 29, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared X.org
X.org xorg-server
X.org xwayland
Vendors & Products X.org
X.org xorg-server
X.org xwayland

Thu, 09 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
Title xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
Weaknesses CWE-416
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

X.org Xorg-server Xwayland
cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-07-08T12:42:16.061Z

Reserved: 2026-06-18T09:26:55.988Z

Link: CVE-2026-56000

cve-icon Vulnrichment

Updated: 2026-07-08T12:42:11.968Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-08T00:00:00Z

Links: CVE-2026-56000 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses