AI description
CVE-2026-50258 describes a stack-based buffer overflow vulnerability affecting the X.Org X server and Xwayland. The flaw originates within the `CheckKeyTypes()` function, which fails to adequately verify or restrict non-canonical key types. This oversight allows a malicious client to manipulate key types to excessive shift levels, thereby triggering stack overflows. The vulnerability is identified as an incomplete resolution of a prior security issue, CVE-2025-26597.
- Description
- A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
- Source
- secalert@redhat.com
- NVD status
- Modified
- Products
- x_server, xwayland, enterprise_linux
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
CVE-2026-50258 - Stack buffer overflow in https://t.co/9CxR9It7IS X server and Xwayland. Incomplete fix for CVE-2025-26597 allows crash or privilege escalation via excessive shift levels. CVSS 7.8. No patch available. Mitigate NOW!. #CVE #Xorg #infosec https://t.co/8Biu2wuM7C
@HugoValters
8 Jun 2026
74 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
We released the #XLibre Xserver 25.0.0.24 and 25.1.6 on Jun 05 containing #security fixes for #CVE-2026-50256, CVE-2026-50257, CVE-2026-50258, CVE-2026-50259, CVE-2026-50260, CVE-2026-50261, CVE-2026-50262, and CVE-2026-50263. https://t.co/hzPYknqFK5 https://t.co/2cZFhBLHU7
@XLibreDev
6 Jun 2026
2736 Impressions
19 Retweets
139 Likes
4 Bookmarks
7 Replies
2 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2F16F762-98D6-437F-8771-0F6C70AF65FD",
"versionEndExcluding": "21.1.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED4EB1F5-9BBA-4751-9BC6-1639C7E02E0C",
"versionEndExcluding": "24.1.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "7F6FB57C-2BC7-487C-96DD-132683AEB35D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]