CVE-2026-50261: Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()
A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters in SyncChangeCounter().
Any X client that can connect to the server can trigger this issue. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Components affected: xorg-x11-server, xorg-x11-server-Xwayland Versions affected: xorg-x11-server <= 21.1.22, xorg-x11-server-Xwayland <= 24.1.9
Fixed upstream in xorg-server-21.1.23 and xwayland-24.1.12. Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/bdd7bf57af208b1ddf57d4683d67104443b44812
Reported via ZDI-CAN-30164 (Trend Micro Zero Day Initiative). Tracking: PSIRTSUPT-16950.
Other sources
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
— NVD
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.1.12-1 - Upgrade
Upgrade
xorg-x11-serverto a version that resolves this vulnerability.Fixed in 21.1.23 - Upgrade
Upgrade
xorg-x11-server-Xwaylandto a version that resolves this vulnerability.Fixed in 24.1.12 - Compensating control
Limit which X clients can connect to the X server (the issue can be triggered by any X client that can connect).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50261?
The severity of CVE-2026-50261 is classified as high with a score of 7.8.
How do I fix CVE-2026-50261?
To fix CVE-2026-50261, you should update the X.Org X server or Xwayland to the latest patched version.
What type of vulnerability is CVE-2026-50261?
CVE-2026-50261 is a use-after-free vulnerability found in the X.Org X server and Xwayland.
What can attackers do with CVE-2026-50261?
Attackers can exploit CVE-2026-50261 to potentially crash the X server or Xwayland, leading to denial of service.
In which component is CVE-2026-50261 found?
CVE-2026-50261 is found in the X.Org X server and X.Org Xwayland software components.