PT-2026-56335 · X.Org Foundation+1 · Xorg-Server+2

CVE-2026-56000

·

Published

2026-07-08

·

Updated

2026-08-26

CVSS v4.0

9.0

Critical

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions xorg-server versions prior to 21.2.24 xwayland versions prior to 24.1.13
Description Local attackers with an X connection can cause a Heap Use After Free, a condition where the system continues to use a memory address after it has been freed, potentially leading to crashes or arbitrary code execution. This occurs when providing a GLX commit to the X server because the CommonMakeCurrent() function points to memory that may have been reallocated.
Recommendations Update xorg-server to version 21.2.24 or later. Update xwayland to version 24.1.13 or later.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38489
ALSA-2026:38490
AZL-92072
AZL-92265
CVE-2026-56000
ECHO-173C-C9CA-77CE
OPENSUSE-SU-2026:11227-1
OPENSUSE-SU-2026:11244-1
OPENSUSE-SU-2026:21273-1
OPENSUSE-SU-2026:21283-1
SUSE-SU-2026:22617-1
SUSE-SU-2026:2786-1
SUSE-SU-2026:2787-1
SUSE-SU-2026:2788-1
SUSE-SU-2026:2789-1
SUSE-SU-2026:2791-1
ZDI-26-405

Affected Products

Rocky Linux
Xorg-Server
Xwayland