Impact
An error in the XKB geometry handling of the X.Org X Server and XWayland causes a double‑free when an allocation failure occurs. The fault leaves a dangling pointer that can be dereferenced during cleanup, leading to memory corruption. A local user who can send a crafted request to the display server can trigger this flaw, which may result in either a denial of service or arbitrary code execution with the privileges of the display server process.
Affected Systems
The vulnerability affects the X.Org X Server and its XWayland component. No specific version range is listed in the available data, so all installations of these components that have not been patched are considered vulnerable.
Risk and Exploitability
This weakness received a CVSS score of 7.8, indicating a high severity. No EPSS score is available, and the vulnerability is not registered in the CISA KEV catalog. The attack vector is local; a malicious user must have access to the host and be able to communicate with the X display server. Because the flaw can lead to privilege escalation or code execution, the risk to affected systems is significant and demands prompt action.
OpenCVE Enrichment