cbcvebase.

X.Org Xwayland vulnerabilities

58 known vulnerabilities affecting x.org/xwayland.

Total CVEs
58
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH49MEDIUM8

Vulnerabilities

Page 3 of 3
CVE-2025-26600P3HIGHCVSS 7.8fixed in 24.1.62025-02-25
CVE-2025-26600 [HIGH] CWE-416 CVE-2025-26600: A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.
nvdosv
CVE-2025-26594P3HIGHCVSS 7.8fixed in 24.1.62025-02-25
CVE-2025-26594 [HIGH] CWE-416 CVE-2025-26594: A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.
nvdosv
CVE-2025-49179P3HIGHCVSS 7.3fixed in 24.1.72025-06-17
CVE-2025-49179 [HIGH] CWE-190 CVE-2025-49179: A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not c A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.
nvdosv
CVE-2025-26601P3HIGHCVSS 7.8fixed in 24.1.62025-02-25
CVE-2025-26601 [HIGH] CWE-416 CVE-2025-26601: A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the cha A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing
nvdosv
CVE-2024-31080P3HIGHCVSS 7.3≥ 0, < 2:22.1.1-1ubuntu0.132024-04-09
CVE-2024-31080 [HIGH] xorg-server, xwayland regression xorg-server, xwayland regression USN-6721-1 fixed vulnerabilities in X.Org X Server. That fix was incomplete resulting in a regression. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that X.Org X Server incorrectly handled certain data. An attacker could possibly use this issue to expose sensitive information. (CVE-2024-31080, CVE-2024-31081, CVE-2024-31082) It was discove
osv
CVE-2024-31081P3HIGHCVSS 7.3≥ 0, < 2:23.2.6-12024-04-04
CVE-2024-31081 [HIGH] CVE-2024-31081: A heap-based buffer over-read vulnerability was found in the X A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read h
osv
CVE-2025-62229P3HIGHCVSS 7.3≥ 1.15.0, < 24.1.92025-10-30
CVE-2025-62229 [HIGH] CWE-416 CVE-2025-62229: A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notificati A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of s
nvdosv
CVE-2025-26599P3HIGHCVSS 7.8fixed in 24.1.62025-02-25
CVE-2025-26599 [HIGH] CWE-824 CVE-2025-26599: An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRe An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an unini
nvdosv
CVE-2024-0409P3HIGHCVSS 7.8fixed in 23.2.42024-01-18
CVE-2024-0409 [HIGH] CWE-787 CVE-2024-0409: A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong typ A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.
nvdosv
CVE-2025-49176P3HIGHCVSS 7.3fixed in 24.1.72025-06-17
CVE-2025-49176 [HIGH] CWE-190 CVE-2025-49176: A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checkin A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
nvdosv
CVE-2022-3551P4MEDIUMCVSS 6.5≥ 0, < 2:22.1.5-12022-10-17
CVE-2022-3551 [MEDIUM] CVE-2022-3551: A vulnerability, which was classified as problematic, has been found in X A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211052.
osv
CVE-2025-49177P4MEDIUMCVSS 6.1fixed in 24.1.72025-06-17
CVE-2025-49177 [MEDIUM] CWE-200 CVE-2025-49177: A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validat A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
nvdosv
CVE-2026-50263P4MEDIUMCVSS 5.5fixed in 24.1.122026-06-05
CVE-2026-50263 [MEDIUM] CWE-416 CVE-2026-50263: A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
nvd
CVE-2026-50262P4MEDIUMCVSS 5.5fixed in 24.1.122026-06-05
CVE-2026-50262 [MEDIUM] CWE-125 CVE-2026-50262: An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableA An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
nvd
CVE-2025-49175P4MEDIUMCVSS 6.1fixed in 24.1.82025-06-17
CVE-2025-49175 [MEDIUM] CWE-125 CVE-2025-49175: A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides n A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.
nvdosv
CVE-2024-0408P4MEDIUMCVSS 5.5fixed in 23.2.42024-01-18
CVE-2024-0408 [MEDIUM] CWE-158 CVE-2024-0408: A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object tha
nvdosv
CVE-2025-49178P4MEDIUMCVSS 5.5fixed in 24.1.72025-06-17
CVE-2025-49178 [MEDIUM] CWE-667 CVE-2025-49178: A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's reques A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.
nvdosv
CVE-2023-5380P4MEDIUMCVSS 4.7fixed in 23.2.22023-10-25
CVE-2023-5380 [MEDIUM] CWE-416 CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specif A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed follo
nvd
X.Org Xwayland vulnerabilities | cvebase