Impact
The vulnerability exists in the GLX component of the X.Org X11 server, where the interface does not verify that incoming data sizes remain within allocated buffer limits during large rendering requests. This oversight allows a local authenticated client to send a crafted request, triggering a heap‑based overflow that can lead to arbitrary code execution with the privileges of the X server. If exploitation fails to achieve code execution, the overflow can still corrupt memory and cause the server to crash, resulting in a denial of service.
Affected Systems
The affected product is xorg‑x11‑server (X.Org). Specific versions impacted are not listed in the advisory; check the vendor’s security notices for patched releases and upgrade accordingly.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is not available, so exploitation probability cannot be quantified at present, and the vulnerability is not listed in CISA KEV. The flaw is exploitable only by an authenticated local user. Based on the description, the likely attack vector is a local authenticated client that has permission to access the X server, which could be a legitimate user running graphical applications. Because the vulnerability requires local access, the risk is limited to machines with compromised or malicious local accounts.
OpenCVE Enrichment