ZDI-26-391: X.Org Server miSyncDestroyFence Use-After-Free Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50257.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-391?
ZDI-26-391 has a CVSS rating of 7.8 which indicates a high severity level.
How do I fix ZDI-26-391?
Updating to the latest version of X.Org Server that addresses this specific vulnerability will remediate ZDI-26-391.
Who is affected by ZDI-26-391?
ZDI-26-391 affects installations of X.Org Server that allow local attackers to escalate their privileges.
Can ZDI-26-391 be exploited remotely?
No, ZDI-26-391 requires local access to the system, meaning the attacker must already have the capability to execute low-privileged code on the target.
What type of vulnerability is ZDI-26-391?
ZDI-26-391 is a use-after-free vulnerability that can lead to privilege escalation on vulnerable installations of X.Org Server.