ZDI-26-406: X.Org Server BitmapScaleBitmaps Integer Overflow Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56001.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-406?
ZDI-26-406 has a CVSS rating of 7.8, indicating a high severity risk.
How do I fix ZDI-26-406?
To fix ZDI-26-406, you should update your X.Org Server to the latest version provided by the X.Org Foundation.
Who is affected by ZDI-26-406?
Any system running an affected installation of X.Org Server is vulnerable to ZDI-26-406.
Can ZDI-26-406 be exploited remotely?
No, ZDI-26-406 requires local access to the system to execute low-privileged code before exploitation.
What type of vulnerability is ZDI-26-406?
ZDI-26-406 is an integer overflow privilege escalation vulnerability.