X.Org Xwayland vulnerabilities
58 known vulnerabilities affecting x.org/xwayland.
Total CVEs
58
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH49MEDIUM8
Vulnerabilities
Page 2 of 3
CVE-2022-2320P3HIGHCVSS 7.8≥ 0, < 2:22.1.3-12022-09-01
CVE-2022-2320 [HIGH] CVE-2022-2320: A flaw was found in the Xorg-x11-server
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.
osv
CVE-2026-50257P3HIGHCVSS 7.8fixed in 24.1.122026-06-05
CVE-2026-50257 [HIGH] CWE-416 CVE-2026-50257: A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This m
nvd
CVE-2023-6478P3HIGHCVSS 7.5fixed in 23.2.32023-12-13
CVE-2023-6478 [HIGH] CWE-190 CVE-2023-6478: A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChange
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
nvdosv
CVE-2025-26595P3HIGHCVSS 7.8fixed in 24.1.62025-02-25
CVE-2025-26595 [HIGH] CWE-121 CVE-2025-26595: A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fi
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.
nvdosv
CVE-2025-26598P3HIGHCVSS 7.8fixed in 24.1.62025-02-25
CVE-2025-26598 [HIGH] CWE-787 CVE-2025-26598: An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searche
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memo
nvdosv
CVE-2025-49180P3HIGHCVSS 7.8fixed in 24.1.72025-06-17
CVE-2025-49180 [HIGH] CWE-190 CVE-2025-49180: A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not proper
A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocate.
nvdosv
CVE-2025-62231P3HIGHCVSS 7.3fixed in 24.1.92025-10-30
CVE-2025-62231 [HIGH] CWE-190 CVE-2025-62231: A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds check
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
nvdosv
CVE-2022-4283P3HIGHCVSS 7.8≥ 0, < 2:22.1.6-12022-12-14
CVE-2022-4283 [HIGH] CVE-2022-4283: A vulnerability was found in X
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
osv
CVE-2023-0494P3HIGHCVSS 7.8≥ 0, < 2:22.1.8-12023-03-27
CVE-2023-0494 [HIGH] CVE-2023-0494: A vulnerability was found in X
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
osv
CVE-2024-9632P3HIGHCVSS 7.8≥ 0, < 2:24.1.4-12024-10-30
CVE-2024-9632 [HIGH] CVE-2024-9632: A flaw was found in the X
A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.
osv
CVE-2023-5367P3HIGHCVSS 7.8fixed in 23.2.22023-10-25
CVE-2023-5367 [HIGH] CWE-787 CVE-2023-5367: A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect c
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
nvdosv
CVE-2021-4010P3HIGHCVSS 7.8≥ 0, < 2:21.1.4-12021-12-17
CVE-2021-4010 [HIGH] CVE-2021-4010: A flaw was found in xorg-x11-server in versions before 21
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
osv
CVE-2021-4009P3HIGHCVSS 7.8≥ 0, < 2:21.1.4-12021-12-17
CVE-2021-4009 [HIGH] CVE-2021-4009: A flaw was found in xorg-x11-server in versions before 21
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
osv
CVE-2021-4008P3HIGHCVSS 7.8≥ 0, < 2:21.1.4-12021-12-17
CVE-2021-4008 [HIGH] CVE-2021-4008: A flaw was found in xorg-x11-server in versions before 21
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
osv
CVE-2021-4011P3HIGHCVSS 7.8≥ 0, < 2:21.1.4-12021-12-17
CVE-2021-4011 [HIGH] CVE-2021-4011: A flaw was found in xorg-x11-server in versions before 21
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
osv
CVE-2025-26597P3HIGHCVSS 7.8fixed in 24.1.62025-02-25
CVE-2025-26597 [HIGH] CWE-119 CVE-2025-26597: A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size.
nvdosv
CVE-2025-26596P3HIGHCVSS 7.8fixed in 24.1.62025-02-25
CVE-2025-26596 [HIGH] CWE-787 CVE-2025-26596: A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySym
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
nvdosv
CVE-2026-56000P3HIGHCVSS 7.8fixed in 24.1.132026-07-08
CVE-2026-56000 [HIGH] CWE-416 CVE-2026-56000: Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
nvd
CVE-2025-62230P3HIGHCVSS 7.3fixed in 24.1.92025-10-30
CVE-2025-62230 [HIGH] CWE-416 CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resour
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
nvdosv
CVE-2022-2319P3HIGHCVSS 7.8≥ 0, < 2:22.1.3-12022-09-01
CVE-2022-2319 [HIGH] CVE-2022-2319: A flaw was found in the Xorg-x11-server
A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length.
osv