Impact
A use‑after‑free flaw in the xorg‑x11‑server Present extension allows an authenticated local X client to create cross‑window notifications and then delete the target window. The server may access freed memory during the notification cleanup, causing it to crash. Successful exploitation results in a denial of service, and the memory access could expose data that existed in the freed buffer, potentially leading to limited information disclosure.
Affected Systems
The vulnerability affects the xorg‑x11‑server package, but no specific version information is provided in the CVE record. All installations of this server component that include the Present extension may be impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog. It is inferred that the attack vector is local, requiring an authenticated X client with the ability to orchestrate cross‑window notifications before destroying a window. Exploitation requires no network or elevated privileges beyond those normally granted to a local X client. The primary impact is a crash of the X server, which can be disruptive to all users of that server instance. The potential for information disclosure exists but is not asserted as a guaranteed outcome.
OpenCVE Enrichment