ZDI-26-397: X.Org Server CreateSaverWindow Use-After-Free Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-50263.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-397?
ZDI-26-397 has a CVSS rating of 5.5, indicating it is of medium severity.
How do I fix ZDI-26-397?
To fix ZDI-26-397, update to the latest version of X.Org Server that addresses this vulnerability.
Who can exploit ZDI-26-397?
ZDI-26-397 can be exploited by local attackers who have the ability to execute low-privileged code on the target system.
What type of vulnerability is ZDI-26-397?
ZDI-26-397 is classified as a use-after-free vulnerability that allows for information disclosure.
Which software is affected by ZDI-26-397?
ZDI-26-397 affects installations of the X.Org Server developed by the X.Org Foundation.