CVE-2026-50261

Summary

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Enterprise Linux 100:24.1.9-4.el10_2.2 < *unaffected
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:24.1.5-6.el10_0.1 < *unaffected
Red HatRed Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION0:1.1.0-25.el6_10.18 < *unaffected
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:1.20.4-35.el7_9 < *unaffected
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:1.8.0-36.el7_9.5 < *unaffected
Red HatRed Hat Enterprise Linux 80:21.1.3-20.el8_10.2 < *unaffected
Red HatRed Hat Enterprise Linux 80:1.20.11-28.el8_10.2 < *unaffected
Red HatRed Hat Enterprise Linux 80:1.15.0-10.el8_10 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:1.20.10-5.el8_4 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:1.11.0-8.el8_4.16 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:1.20.10-5.el8_4 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:1.11.0-8.el8_4.16 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:1.20.11-8.el8_6 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:21.1.3-2.el8_6.7 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:1.12.0-6.el8_6.18 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:1.20.11-8.el8_6 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:21.1.3-2.el8_6.7 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:1.12.0-6.el8_6.18 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:1.20.11-19.el8_8 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:21.1.3-13.el8_8.1 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:1.12.0-15.el8_8.18 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:1.20.11-19.el8_8 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:21.1.3-13.el8_8.1 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:1.12.0-15.el8_8.18 < *unaffected
Red HatRed Hat Enterprise Linux 90:24.1.9-4.el9_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 90:1.20.11-34.el9_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 90:1.15.0-7.el9_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:1.20.11-21.el9_2 < *unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:21.1.3-10.el9_2.1 < *unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:1.12.0-14.el9_2.15 < *unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:1.20.11-29.el9_4 < *unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:22.1.9-8.el9_4.1 < *unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:1.13.1-8.el9_4.10 < *unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:1.20.11-34.el9_6 < *unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:23.2.7-6.el9_6.1 < *unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:1.14.1-11.el9_6 < *unaffected

Weaknesses

  • CWE-416: Use After Free

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter()

Additional References

References