Medium severity5.5NVD Advisory· Published Jun 5, 2026· Updated Jun 15, 2026
CVE-2026-50262
CVE-2026-50262
Description
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
26cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords17 versionspkg:rpm/almalinux/tigervncpkg:rpm/almalinux/tigervnc-iconspkg:rpm/almalinux/tigervnc-licensepkg:rpm/almalinux/tigervnc-selinuxpkg:rpm/almalinux/tigervnc-serverpkg:rpm/almalinux/tigervnc-server-minimalpkg:rpm/almalinux/tigervnc-server-modulepkg:rpm/almalinux/xorg-x11-server-commonpkg:rpm/almalinux/xorg-x11-server-develpkg:rpm/almalinux/xorg-x11-server-sourcepkg:rpm/almalinux/xorg-x11-server-Xdmxpkg:rpm/almalinux/xorg-x11-server-Xephyrpkg:rpm/almalinux/xorg-x11-server-Xnestpkg:rpm/almalinux/xorg-x11-server-Xorgpkg:rpm/almalinux/xorg-x11-server-Xvfbpkg:rpm/almalinux/xorg-x11-server-Xwaylandpkg:rpm/almalinux/xorg-x11-server-Xwayland-devel
< 1.15.0-10.el8_10+ 16 more
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.15.0-10.el8_10
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 1.20.11-34.el9_8.2
- (no CPE)range: < 21.1.3-20.el8_10.2
- (no CPE)range: < 24.1.9-4.el9_8.2
Patches
Vulnerability mechanics
References
5- gitlab.freedesktop.org/xorg/xserver/-/commit/6d459e4daf715bea8abdafa8fb130be2f8a1d145nvdPatch
- access.redhat.com/security/cve/CVE-2026-50262nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- lists.x.org/archives/xorg-announce/2026-June/003702.htmlnvdMailing ListVendor Advisory
- redhat.atlassian.net/browse/PSIRTSUPT-16950nvdPermissions Required
News mentions
3- ZDI-26-396: X.Org Server ChangeDrawableAttributes Out-Of-Bounds Read Information Disclosure VulnerabilityZero Day Initiative · Jun 24, 2026
- Patch Tuesday - June 2026Rapid7 Blog · Jun 9, 2026
- Xorg X server: Nine High-Severity Flaws Disclosed TogetherVypr Intelligence · Jun 5, 2026