Description
A flaw was found in xorg-x11-server. A use-after-free vulnerability, where the application accesses memory after it has already been released, occurs in the Present extension because window notification entries are not properly unlinked before cleaning up window resources. An authenticated local X client can exploit this flaw by creating cross-window notifications and subsequently destroying the target window. Successful exploitation primarily results in a Denial of Service (DoS) via an X server crash, and may potentially lead to information disclosure.
Published: n/a
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A use‑after‑free flaw in the xorg‑x11‑server Present extension allows an authenticated local X client to create cross‑window notifications and then delete the target window. The server may access freed memory during the notification cleanup, causing it to crash. Successful exploitation results in a denial of service, and the memory access could expose data that existed in the freed buffer, potentially leading to limited information disclosure.

Affected Systems

The vulnerability affects the xorg‑x11‑server package, but no specific version information is provided in the CVE record. All installations of this server component that include the Present extension may be impacted.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog. It is inferred that the attack vector is local, requiring an authenticated X client with the ability to orchestrate cross‑window notifications before destroying a window. Exploitation requires no network or elevated privileges beyond those normally granted to a local X client. The primary impact is a crash of the X server, which can be disruptive to all users of that server instance. The potential for information disclosure exists but is not asserted as a guaranteed outcome.

Generated by OpenCVE AI on October 8, 2026 at 13:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest xorg‑x11‑server update that incorporates the present extension fix
  • If a patch is not yet available, disable the Present extension to prevent cross‑window notifications until the fix is applied
  • Limit local X client access to trusted users only to reduce the risk of malicious exploitation
  • Monitor X server logs for crash events and investigate any unexpected terminations

Generated by OpenCVE AI on October 8, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in xorg-x11-server. A use-after-free vulnerability, where the application accesses memory after it has already been released, occurs in the Present extension because window notification entries are not properly unlinked before cleaning up window resources. An authenticated local X client can exploit this flaw by creating cross-window notifications and subsequently destroying the target window. Successful exploitation primarily results in a Denial of Service (DoS) via an X server crash, and may potentially lead to information disclosure.
Title xorg-x11-server: Present Extension Cross-Window Notify Use-After-Free
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-07T12:00:00Z

Links: CVE-2026-93515 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:00:05Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference