Skip to content
Noroxi
CVE-2026-56000· NVD / CVE Program· CNA suse

xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

CriticalCVSS 9.0 · v4.0—No exploit Fix available
Published
Jul 8, 2026
Updated
Jul 9, 2026
EPSS
0.3% · 21th percentile
Follow this CVE

Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.

Report tools

JSON

Action score

36

Monitor

Low priority for now.

CVSS
36 / 40 · 9.0 / 10
CISA KEV
0 / 30 · Not listed
EPSS
0 / 30 · 0.3%

CISA SSVC decision

Exploitation
none
Automatable
no
Technical impact
total

Vulnrichment: CISA's decision-tree inputs.

CNA vs NVD score

NVD
—
CNA · suse
9.0
NVD has not scored this yet; the score shown is the CNA’s.

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

The score given by the assigning authority versus NVD’s independent score. A gap means the severity is contested.

Affected systems

VendorProduct
x.orgx server
x.orgxwayland

Affected versions

NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.

  • x.org x serverbefore 21.2.24
  • x.org xwaylandbefore 24.1.13

Versions reported by the vendor

Affected version ranges reported by the assigning authority (suse). Independent of NVD's CPE analysis and usually ahead of it.

  • X.Org xorg-x11-server

    • before 21.1.24affected · rpm
  • X.Org xwayland

    • before 24.1.13affected · rpmver

Package-level exposure

OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.

EcosystemPackageAffected rangeFix
AlmaLinux:10xorg-x11-server-Xwaylandbefore 24.1.9-4.el10_2.324.1.9-4.el10_2.3
AlmaLinux:10xorg-x11-server-Xwayland-develbefore 24.1.9-4.el10_2.324.1.9-4.el10_2.3
AlmaLinux:9xorg-x11-server-Xwaylandbefore 24.1.9-4.el9_8.324.1.9-4.el9_8.3
AlmaLinux:9xorg-x11-server-Xwayland-develbefore 24.1.9-4.el9_8.324.1.9-4.el9_8.3
Debian:12xorg-serverall versions—
Debian:12xwaylandall versions—
Debian:13xorg-serverbefore 2:21.1.16-1.3+deb13u42:21.1.16-1.3+deb13u4
Debian:14xorg-serverbefore 2:21.1.24-12:21.1.24-1
Debian:14xwaylandbefore 2:24.1.13-12:24.1.13-1
openSUSE:Leap 16.0xorg-x11-serverbefore 21.1.15-160000.6.121.1.15-160000.6.1
openSUSE:Leap 16.0xwaylandbefore 24.1.6-160000.6.124.1.6-160000.6.1
openSUSE:Tumbleweedxorg-x11-serverbefore 21.1.21-8.121.1.21-8.1
openSUSE:Tumbleweedxwaylandbefore 24.1.12-1.124.1.12-1.1
Red Hat:enterprise_linux_eus:10.0xorg-x11-server-Xwaylandbefore 0:24.1.5-6.el10_0.20:24.1.5-6.el10_0.2
Red Hat:enterprise_linux_eus:10.0xorg-x11-server-Xwayland-debuginfobefore 0:24.1.5-6.el10_0.20:24.1.5-6.el10_0.2
Red Hat:enterprise_linux_eus:10.0xorg-x11-server-Xwayland-debugsourcebefore 0:24.1.5-6.el10_0.20:24.1.5-6.el10_0.2
Red Hat:enterprise_linux_eus:10.0xorg-x11-server-Xwayland-develbefore 0:24.1.5-6.el10_0.20:24.1.5-6.el10_0.2
Red Hat:enterprise_linux:10.2xorg-x11-server-Xwaylandbefore 0:24.1.9-4.el10_2.30:24.1.9-4.el10_2.3
Red Hat:enterprise_linux:10.2xorg-x11-server-Xwayland-debuginfobefore 0:24.1.9-4.el10_2.30:24.1.9-4.el10_2.3
Red Hat:enterprise_linux:10.2xorg-x11-server-Xwayland-debugsourcebefore 0:24.1.9-4.el10_2.30:24.1.9-4.el10_2.3
Red Hat:enterprise_linux:10.2xorg-x11-server-Xwayland-develbefore 0:24.1.9-4.el10_2.30:24.1.9-4.el10_2.3
Red Hat:enterprise_linux:9::appstreamxorg-x11-server-Xwaylandbefore 0:24.1.9-4.el9_8.30:24.1.9-4.el9_8.3
Red Hat:enterprise_linux:9::appstreamxorg-x11-server-Xwayland-debuginfobefore 0:24.1.9-4.el9_8.30:24.1.9-4.el9_8.3
Red Hat:enterprise_linux:9::appstreamxorg-x11-server-Xwayland-debugsourcebefore 0:24.1.9-4.el9_8.30:24.1.9-4.el9_8.3

+16

Other highest-scoring records for the same primary product.

  • CVE-2023-6816Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer
    40Plan
  • CVE-2007-6427The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte
    38Monitor
  • CVE-2026-34002Xorg: xwayland: x.org x server: information disclosure or denial of service via out-of-bounds read in xkb modifier map handling
    36Monitor
  • CVE-2026-34000Xwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing.
    36Monitor
  • CVE-2022-46344A vulnerability was found in X.Org.
    36Monitor
  • CVE-2022-46343A vulnerability was found in X.Org.
    36Monitor

Remediation

Which version to upgrade to

Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.

Product / packageFixed versionSource
X.Org xorg-x11-server21.1.24Vendor (CNA)
X.Org xwayland24.1.13Vendor (CNA)
azl3 xorg-x11-server-Xwayland 24.1.12-1 on Azure Linux 3.024.1.13-1 · CBL-Mariner ReleasesMicrosoft (MSRC)
almalinux:xorg-x11-server-Xwayland24.1.9-4.el10_2.3 · AlmaLinux:10Package registry (OSV)
almalinux:xorg-x11-server-Xwayland-devel24.1.9-4.el10_2.3 · AlmaLinux:10Package registry (OSV)
debian:xorg-server2:21.1.16-1.3+deb13u4 · Debian:13Package registry (OSV)
debian:xwayland2:24.1.13-1 · Debian:14Package registry (OSV)
opensuse:xorg-x11-server21.1.21-8.1 · openSUSE:TumbleweedPackage registry (OSV)
opensuse:xwayland24.1.12-1.1 · openSUSE:TumbleweedPackage registry (OSV)
red hat:xorg-x11-server-Xwayland0:24.1.9-4.el10_2.3 · Red Hat:enterprise_linux:10.2Package registry (OSV)
red hat:xorg-x11-server-Xwayland-debuginfo0:24.1.9-4.el10_2.3 · Red Hat:enterprise_linux:10.2Package registry (OSV)
red hat:xorg-x11-server-Xwayland-debugsource0:24.1.9-4.el10_2.3 · Red Hat:enterprise_linux:10.2Package registry (OSV)
red hat:xorg-x11-server-Xwayland-devel0:24.1.9-4.el10_2.3 · Red Hat:enterprise_linux:10.2Package registry (OSV)
rocky linux:xorg-x11-server-Xwayland0:24.1.9-4.el10_2.3 · Rocky Linux:10Package registry (OSV)
suse:xorg-x11-server21.1.11-150600.5.31.1 · SUSE:Linux Enterprise Server 15 SP6-LTSSPackage registry (OSV)
suse:xwayland24.1.6-160000.6.1 · SUSE:Linux Enterprise Server 16.0Package registry (OSV)

Exploit status

No known public exploit

No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.

Research context

For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.

Timeline

From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.

No dated events beyond publication.

EPSS, last 120 days

FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).

Patch and commit links

Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.

Finders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.

Variant candidates

Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.

  • CVE-2026-5025733 days apartXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()
    31Monitor
  • CVE-2026-5026033 days apartXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
    31Monitor
  • CVE-2026-5026133 days apartXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()
    31Monitor
  • CVE-2025-26594498 days apartX.org: xwayland: use-after-free of the root cursor
    31Monitor
  • CVE-2025-26600498 days apartXorg: xwayland: use-after-free in playreleasedevents()
    31Monitor
  • CVE-2025-26601498 days apartXorg: xwayland: use-after-free in syncinittrigger()
    31Monitor

Chain candidates

An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.

—

Bug bounty scope

No known public program.

Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).

Technical details

Attack conditions

  • Anyone who can reach it over the internet can trigger it.
  • A low-privileged account is enough.
  • No user action is required.
  • Special conditions such as timing or configuration are required.

If successful

Confidentiality
Integrity
Availability
Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
X

Weakness class (CWE)

CWE-416 · Use After Free

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

nvd-secondary

Root cause

After a memory region is freed, another reference pointing to it is still used. By then, the same region may have been allocated for different data.

A representative example of this vulnerability class. Not the vendor's source code; it shows the faulty pattern and its fix.

Vulnerable

c
free(dev->buf);/* ... another thread is still running ... */process(dev->buf);

Fixed

c
lock(&dev->lock);free(dev->buf);dev->buf = NULL;unlock(&dev->lock);

Attack context

MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.

MITRE has no CAPEC/ATT&CK mapping for this CWE.

Noroxi analysis

No Noroxi analysis for this record yet

We don't hand-write analysis for all 385,000+ vulnerabilities; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.

We use this product, ask for help

Change log

  1. Fix✗ → ✓

For records you follow, these changes also arrive as notifications. →

References

All records