CVE-2026-50258High· 7.8▾ TwilightA stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to Xkb…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
x_server < 21.1.23xwayland < 24.1.12enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Upgrade past the affected range:
x_server 21.1.23xwayland 24.1.12Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50259High· 7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland
CVE-2026-50256High· 7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland
CVE-2026-50264High· 7.8An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat
CVE-2026-50263Medium· 5.5A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow()
CVE-2026-50262Medium· 5.5An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes()
CVE-2026-50261High· 7.8A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter()