ZDI-26-392: X.Org Server Xkb Key Types Stack-based Buffer Overflow Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50258.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-392?
ZDI-26-392 has been assigned a CVSS rating of 7.8, indicating a high severity level.
How do I fix ZDI-26-392?
To mitigate ZDI-26-392, update your X.Org Server to the latest version that addresses this vulnerability.
What does ZDI-26-392 exploit?
ZDI-26-392 exploits a stack-based buffer overflow in X.Org Server's handling of Xkb key types.
Who is affected by ZDI-26-392?
ZDI-26-392 affects installations of the X.Org Server that allow local attackers to escalate privileges.
What are the prerequisites for exploiting ZDI-26-392?
An attacker must first have the ability to execute low-privileged code on the target system to exploit ZDI-26-392.