CVE-2026-50260: Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection in FreeCounter().
Any X client that can connect to the server can trigger this issue. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Components affected: xorg-x11-server, xorg-x11-server-Xwayland Versions affected: xorg-x11-server <= 21.1.22, xorg-x11-server-Xwayland <= 24.1.9
Fixed upstream in xorg-server-21.1.23 and xwayland-24.1.12. Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b
Reported via ZDI-CAN-30163 (Trend Micro Zero Day Initiative). Tracking: PSIRTSUPT-16950.
Other sources
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
— NVD
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.1.12-1 - Upgrade
Upgrade
xorg-x11-serverto a version that resolves this vulnerability.Fixed in 21.1.23 - Upgrade
Upgrade
xorg-x11-server-Xwaylandto a version that resolves this vulnerability.Fixed in 24.1.12 - Compensating control
Because any X client that can connect to the server can trigger this issue, restrict access to the X server (and Xwayland) so only trusted clients can connect (e.g., limit network access and/or allow only specific local users/hosts to reach the X display).
- Compensating control
As a mitigation for potential crash/privilege escalation, avoid running the X server as root.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50260?
The severity of CVE-2026-50260 is high, with a score of 7.8.
How do I fix CVE-2026-50260?
To fix CVE-2026-50260, update to the latest version of the X.Org X server and Xwayland that contains the patch.
What impact does CVE-2026-50260 have?
CVE-2026-50260 can lead to a crash of the X server or potentially allow for privilege escalation.
What type of flaw is CVE-2026-50260?
CVE-2026-50260 is classified as a use-after-free vulnerability in the X.Org X server.
Which software is affected by CVE-2026-50260?
CVE-2026-50260 affects the X.Org X server and X.Org Xwayland components.