CVE-2026-50259

Summary

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Enterprise Linux 100:24.1.9-4.el10_2.2 < *unaffected
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:24.1.5-6.el10_0.1 < *unaffected
Red HatRed Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION0:1.1.0-25.el6_10.18 < *unaffected
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:1.20.4-35.el7_9 < *unaffected
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:1.8.0-36.el7_9.5 < *unaffected
Red HatRed Hat Enterprise Linux 80:21.1.3-20.el8_10.2 < *unaffected
Red HatRed Hat Enterprise Linux 80:1.20.11-28.el8_10.2 < *unaffected
Red HatRed Hat Enterprise Linux 80:1.15.0-10.el8_10 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:1.20.10-5.el8_4 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:1.11.0-8.el8_4.16 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:1.20.10-5.el8_4 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:1.11.0-8.el8_4.16 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:1.20.11-8.el8_6 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:21.1.3-2.el8_6.7 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:1.12.0-6.el8_6.18 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:1.20.11-8.el8_6 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:21.1.3-2.el8_6.7 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:1.12.0-6.el8_6.18 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:1.20.11-19.el8_8 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:21.1.3-13.el8_8.1 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:1.12.0-15.el8_8.18 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:1.20.11-19.el8_8 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:21.1.3-13.el8_8.1 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:1.12.0-15.el8_8.18 < *unaffected
Red HatRed Hat Enterprise Linux 90:24.1.9-4.el9_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 90:1.20.11-34.el9_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 90:1.15.0-7.el9_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:1.20.11-21.el9_2 < *unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:21.1.3-10.el9_2.1 < *unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:1.12.0-14.el9_2.15 < *unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:1.20.11-29.el9_4 < *unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:22.1.9-8.el9_4.1 < *unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:1.13.1-8.el9_4.10 < *unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:1.20.11-34.el9_6 < *unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:23.2.7-6.el9_6.1 < *unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:1.14.1-11.el9_6 < *unaffected

Weaknesses

  • CWE-121: Stack-based Buffer Overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing

Additional References

References