High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-56000
CVE-2026-56000
Description
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
Affected products
6- osv-coords6 versionspkg:apk/chainguard/xorg-serverpkg:apk/wolfi/xorg-serverpkg:rpm/opensuse/xorg-x11-server&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/xorg-x11-server&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/xwayland&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/xwayland&distro=openSUSE%20Tumbleweed
< 21.1.24-r0+ 5 more
- (no CPE)range: < 21.1.24-r0
- (no CPE)range: < 21.1.24-r0
- (no CPE)range: < 21.1.15-160000.6.1
- (no CPE)range: < 21.1.21-8.1
- (no CPE)range: < 24.1.6-160000.6.1
- (no CPE)range: < 24.1.12-1.1
Patches
Vulnerability mechanics
References
2- gitlab.freedesktop.org/xorg/xserver/-/commit/2779affbdb4354e894f490e56f962527d6125043nvdPatch
- www.openwall.com/lists/oss-security/2026/07/08/2nvdMailing ListPatchThird Party Advisory
News mentions
0No linked articles in our index yet.