Description
A flaw was found in the X.Org X Server and XWayland. An error handling issue in the X Keyboard Extension (XKB) geometry processing fails to clear a memory pointer after an allocation failure, leading to a double-free condition during cleanup. A local user can exploit this vulnerability by sending a specially crafted request to the display server. This can cause memory corruption, potentially resulting in a Denial of Service (DoS) or arbitrary code execution with elevated privileges.
Published: n/a
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

An error in the XKB geometry handling of the X.Org X Server and XWayland causes a double‑free when an allocation failure occurs. The fault leaves a dangling pointer that can be dereferenced during cleanup, leading to memory corruption. A local user who can send a crafted request to the display server can trigger this flaw, which may result in either a denial of service or arbitrary code execution with the privileges of the display server process.

Affected Systems

The vulnerability affects the X.Org X Server and its XWayland component. No specific version range is listed in the available data, so all installations of these components that have not been patched are considered vulnerable.

Risk and Exploitability

This weakness received a CVSS score of 7.8, indicating a high severity. No EPSS score is available, and the vulnerability is not registered in the CISA KEV catalog. The attack vector is local; a malicious user must have access to the host and be able to communicate with the X display server. Because the flaw can lead to privilege escalation or code execution, the risk to affected systems is significant and demands prompt action.

Generated by OpenCVE AI on October 8, 2026 at 13:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest X.Org X Server and XWayland releases that contain the double‑free fix.
  • If an immediate update is not possible, limit the set of users that can connect to the X display server by configuring Xorg to accept connections only from trusted accounts or by using a secure authentication method such as MIT-MAGIC-COOKIE-1 with a strong cookie.
  • As a complementary measure, consider disabling or limiting XKB geometry processing where feasible, or configuring the display server to run as a non‑privileged user to contain potential exploitation.

Generated by OpenCVE AI on October 8, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the X.Org X Server and XWayland. An error handling issue in the X Keyboard Extension (XKB) geometry processing fails to clear a memory pointer after an allocation failure, leading to a double-free condition during cleanup. A local user can exploit this vulnerability by sending a specially crafted request to the display server. This can cause memory corruption, potentially resulting in a Denial of Service (DoS) or arbitrary code execution with elevated privileges.
Title xorg-x11-server: xwayland: xorg-x11-server: Arbitrary code execution via double-free in XKB geometry handling
Weaknesses CWE-1341
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-07T12:00:00Z

Links: CVE-2026-88812 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:00:05Z

Weaknesses
  • CWE-1341

    Multiple Releases of Same Resource or Handle