ZDI-26-409: X.Org Server Glamor Font Heap-based Buffer Overflow Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-55999.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-409?
ZDI-26-409 has a CVSS rating of 7.8, indicating a high severity risk.
How do I fix ZDI-26-409?
To mitigate ZDI-26-409, you should update to the latest secure version of X.Org Server that addresses this vulnerability.
Who is affected by ZDI-26-409?
ZDI-26-409 affects installations of X.Org Server where local attackers can exploit a privilege escalation vulnerability.
What type of vulnerability is ZDI-26-409?
ZDI-26-409 is classified as a buffer overflow vulnerability that can lead to local privilege escalation.
What must an attacker do to exploit ZDI-26-409?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-26-409.