CVE-2026-50263: Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()
A client can trigger a use-after-free read after changing window attributes and forcing the screen saver in CreateSaverWindow(), leading to information disclosure.
Any X client that can connect to the server can trigger this issue.
Components affected: xorg-x11-server, xorg-x11-server-Xwayland Versions affected: xorg-x11-server <= 21.1.22, xorg-x11-server-Xwayland <= 24.1.9
Fixed upstream in xorg-server-21.1.23 and xwayland-24.1.12. Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/ecc634f1b2f7aa473d3a267eada98c4918bf9e05
Reported via ZDI-CAN-30168 (Trend Micro Zero Day Initiative). Tracking: PSIRTSUPT-16950.
Other sources
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
— NVD
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.1.12-1 - Upgrade
Upgrade
xorg-x11-serverto a version that resolves this vulnerability.Fixed in 21.1.23 - Upgrade
Upgrade
xorg-x11-server-Xwaylandto a version that resolves this vulnerability.Fixed in 24.1.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ecc634f1b2f7aa473d3a267eada98c4918bf9e05 - Compensating control
Because “Any X client that can connect to the server can trigger this issue,” restrict which clients can connect to the X server/Xwayland (e.g., limit network/firewall access and only allow trusted clients).
- Operational
After upgrading xorg-x11-server and xorg-x11-server-Xwayland to the fixed versions, review for any potential information disclosure from the affected CreateSaverWindow() use-after-free and rotate any potentially exposed secrets/credentials if applicable.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50263?
CVE-2026-50263 has a medium severity rating of 5.5.
What type of vulnerability is CVE-2026-50263?
CVE-2026-50263 is classified as a use-after-free vulnerability.
How do I fix CVE-2026-50263?
To fix CVE-2026-50263, update the X.Org X server and Xwayland to the latest version that patches this vulnerability.
What is the impact of CVE-2026-50263?
CVE-2026-50263 may lead to information disclosure due to a use-after-free flaw.
Which software is affected by CVE-2026-50263?
CVE-2026-50263 affects the X.Org X Server and X.Org Xwayland.