High severity7.8NVD Advisory· Published Jun 5, 2026· Updated Jun 8, 2026
CVE-2026-50256
CVE-2026-50256
Description
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
25cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords17 versionspkg:rpm/almalinux/tigervncpkg:rpm/almalinux/tigervnc-iconspkg:rpm/almalinux/tigervnc-licensepkg:rpm/almalinux/tigervnc-selinuxpkg:rpm/almalinux/tigervnc-serverpkg:rpm/almalinux/tigervnc-server-minimalpkg:rpm/almalinux/tigervnc-server-modulepkg:rpm/almalinux/xorg-x11-server-commonpkg:rpm/almalinux/xorg-x11-server-develpkg:rpm/almalinux/xorg-x11-server-sourcepkg:rpm/almalinux/xorg-x11-server-Xdmxpkg:rpm/almalinux/xorg-x11-server-Xephyrpkg:rpm/almalinux/xorg-x11-server-Xnestpkg:rpm/almalinux/xorg-x11-server-Xorgpkg:rpm/almalinux/xorg-x11-server-Xvfbpkg:rpm/almalinux/xorg-x11-server-Xwaylandpkg:rpm/almalinux/xorg-x11-server-Xwayland-devel
< 1.15.0-10.el8_10+ 16 more
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 21.1.3-20.el8_10.2
- (no CPE)range: < 24.1.9-4.el9_8.2
Patches
Vulnerability mechanics
References
5- gitlab.freedesktop.org/xorg/xserver/-/commit/bb5158f962dc935e58ef8b4b5fcb31be201a6e07nvdPatch
- access.redhat.com/security/cve/CVE-2026-50256nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- lists.x.org/archives/xorg-announce/2026-June/003702.htmlnvdMailing ListThird Party Advisory
- redhat.atlassian.net/browse/PSIRTSUPT-16950nvdPermissions Required
News mentions
3- ZDI-26-390: X.Org Server Font Alias Stack-based Buffer Overflow Privilege Escalation VulnerabilityZero Day Initiative · Jun 24, 2026
- Patch Tuesday - June 2026Rapid7 Blog · Jun 9, 2026
- Xorg X server: Nine High-Severity Flaws Disclosed TogetherVypr Intelligence · Jun 5, 2026