High severity7.8NVD Advisory· Published Jun 5, 2026· Updated Jun 8, 2026
CVE-2026-50258
CVE-2026-50258
Description
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
26cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords17 versionspkg:rpm/almalinux/tigervncpkg:rpm/almalinux/tigervnc-iconspkg:rpm/almalinux/tigervnc-licensepkg:rpm/almalinux/tigervnc-selinuxpkg:rpm/almalinux/tigervnc-serverpkg:rpm/almalinux/tigervnc-server-minimalpkg:rpm/almalinux/tigervnc-server-modulepkg:rpm/almalinux/xorg-x11-server-commonpkg:rpm/almalinux/xorg-x11-server-develpkg:rpm/almalinux/xorg-x11-server-sourcepkg:rpm/almalinux/xorg-x11-server-Xdmxpkg:rpm/almalinux/xorg-x11-server-Xephyrpkg:rpm/almalinux/xorg-x11-server-Xnestpkg:rpm/almalinux/xorg-x11-server-Xorgpkg:rpm/almalinux/xorg-x11-server-Xvfbpkg:rpm/almalinux/xorg-x11-server-Xwaylandpkg:rpm/almalinux/xorg-x11-server-Xwayland-devel
< 1.15.0-10.el8_10+ 16 more
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 21.1.3-20.el8_10.2
- (no CPE)range: < 24.1.9-4.el9_8.2
Patches
Vulnerability mechanics
References
5- gitlab.freedesktop.org/xorg/xserver/-/commit/543e108516428fc8c3bea91d6563ad266f9a801envdPatch
- access.redhat.com/security/cve/CVE-2026-50258nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.x.org/archives/xorg-announce/2026-June/003702.htmlnvdMailing ListThird Party Advisory
- redhat.atlassian.net/browse/PSIRTSUPT-16950nvdPermissions Required
News mentions
3- ZDI-26-392: X.Org Server Xkb Key Types Stack-based Buffer Overflow Privilege Escalation VulnerabilityZero Day Initiative · Jun 24, 2026
- Patch Tuesday - June 2026Rapid7 Blog · Jun 9, 2026
- Xorg X server: Nine High-Severity Flaws Disclosed TogetherVypr Intelligence · Jun 5, 2026