Junglewise Threat Intelligence

CVE-2026-33999: X.Org X server integer underflow in XKB compatibility map handling

CVE-2026-33999 · Severity: high · CVSS 7.8 · Published 2026-04-23

Technologies: X.Org Foundation X Server, Tigervnc. Vendors: X.Org Foundation, Red Hat, X.Org, Tigervnc.

Executive brief

A security vulnerability has been identified in the X.Org X server, a fundamental component used to manage graphical displays and user input on Linux and Unix-like operating systems. An attacker with access to the system can exploit this flaw to cause the display server to crash or potentially gain unauthorized access to sensitive memory. This could lead to a total disruption of the graphical interface or the exposure of private data handled by the system.

Technical details

An integer underflow vulnerability (CWE-191) exists within the X.Org X server's handling of XKB (X Keyboard Extension) compatibility maps. The flaw is triggered when the server processes specially crafted XKB configuration data, leading to a buffer read overrun. An attacker with local or remote X11 server access can exploit this to cause a denial of service (server crash) or achieve out-of-bounds memory access, potentially leading to information disclosure or further memory corruption. The vulnerability affects both standard X.Org servers and Xwayland implementations. Patches have been released by major distributions, including Red Hat, to address the issue in affected packages like xorg-x11-server-Xwayland and TigerVNC.

Affected products

  • X.Org X server All versions prior to patches released April 2026
  • Red Hat xorg-x11-server-Xwayland Enterprise Linux 9, Enterprise Linux 10
  • TigerVNC TigerVNC Versions prior to 1.15.0-6.el9_7.1

Timeline

  • 2026-04-23: disclosed: Vulnerability published in NVD database
  • 2026-04-27: patched: Red Hat released security updates for TigerVNC (RHSA-2026:10739)
  • 2026-04-28: patched: Red Hat released security updates for Xwayland (RHSA-2026:11352)

References

Related threats