Executive brief
A security vulnerability has been identified in the X.Org X server, a fundamental component used to manage graphical displays and user input on Linux systems. A local user could exploit this flaw to crash the system or potentially access sensitive information stored in memory. This could lead to a disruption of services or unauthorized data exposure on affected workstations and servers.
Technical details
An out-of-bounds (OOB) read vulnerability (CWE-125) exists in the X.Org X server's XKB (X Keyboard Extension) key types request validation logic. The flaw is triggered when the server processes a specially crafted XKB request from a local client. Because the server fails to properly validate the request parameters, it may access memory outside of the intended buffer. This can result in a server crash (Denial of Service) or the exposure of sensitive memory contents to the local attacker. The vulnerability affects standard X.Org servers, Xwayland, and TigerVNC components that incorporate X server code. Patches have been released by major distributions including Red Hat.
Affected products
- X.Org X server All versions prior to April 2026 patches
- X.Org Xwayland
- TigerVNC TigerVNC
Timeline
- 2026-04-23: disclosed: CVE published and reported by Red Hat
- 2026-04-27: patched: Red Hat released security updates for RHEL 9 (RHSA-2026:10739)
- 2026-04-28: patched: Red Hat released security updates for RHEL 10 (RHSA-2026:11352)
References
- https://access.redhat.com/errata/RHSA-2026:10739
- https://access.redhat.com/errata/RHSA-2026:11352
- https://access.redhat.com/errata/RHSA-2026:11369
- https://access.redhat.com/errata/RHSA-2026:11388
- https://access.redhat.com/errata/RHSA-2026:11656
- https://access.redhat.com/errata/RHSA-2026:11692
- https://access.redhat.com/errata/RHSA-2026:13414