CVE-2026-50263: Use After Free in Red Hat Red Hat Enterprise Linux 10
This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-50263.
AI Analysis
Technical Summary
A use-after-free vulnerability (CVE-2026-50263) exists in the CreateSaverWindow() function of the X.Org X server and Xwayland on Red Hat Enterprise Linux 10. An attacker with local privileges can trigger a use-after-free read by changing window attributes and forcing the screen saver, which may lead to information disclosure. This issue is part of a set of security flaws fixed in the xorg-x11-server and xorg-x11-server-Xwayland packages. Red Hat has issued official security advisories (RHSA-2026:26566) providing patches that resolve this and other related vulnerabilities. The affected versions are Red Hat Enterprise Linux 10 from 10.0.0 up to but not including 10.2.2. The vulnerability has a CVSS v3.1 score of 5.5 (medium severity) with attack vector local, low attack complexity, low privileges required, no user interaction, unchanged scope, high confidentiality impact, and no integrity or availability impact.
Potential Impact
Successful exploitation of this use-after-free vulnerability can lead to information disclosure on affected systems. The flaw allows a local attacker to read memory after it has been freed, potentially exposing sensitive information. There is no indication of integrity or availability impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability in Red Hat Enterprise Linux 10 starting from version 10.2.2. Users should apply the latest available updates for the xorg-x11-server and xorg-x11-server-Xwayland packages as described in Red Hat Security Advisory RHSA-2026:26566. No additional mitigation steps are required beyond applying the official patches.
CVE-2026-50263: Use After Free in Red Hat Red Hat Enterprise Linux 10
Description
This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-50263.
CVSS v3.1
Score 5.5medium
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 10.0 Extended Update Support
Red Hat
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
Red Hat
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Red Hat
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.6 Extended Update Support
Red Hat
Red Hat Enterprise Linux 9.6 Extended Update Support
Red Hat
Red Hat Enterprise Linux 9.6 Extended Update Support
Red Hat
Red Hat Enterprise Linux 6
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A use-after-free vulnerability (CVE-2026-50263) exists in the CreateSaverWindow() function of the X.Org X server and Xwayland on Red Hat Enterprise Linux 10. An attacker with local privileges can trigger a use-after-free read by changing window attributes and forcing the screen saver, which may lead to information disclosure. This issue is part of a set of security flaws fixed in the xorg-x11-server and xorg-x11-server-Xwayland packages. Red Hat has issued official security advisories (RHSA-2026:26566) providing patches that resolve this and other related vulnerabilities. The affected versions are Red Hat Enterprise Linux 10 from 10.0.0 up to but not including 10.2.2. The vulnerability has a CVSS v3.1 score of 5.5 (medium severity) with attack vector local, low attack complexity, low privileges required, no user interaction, unchanged scope, high confidentiality impact, and no integrity or availability impact.
Potential Impact
Successful exploitation of this use-after-free vulnerability can lead to information disclosure on affected systems. The flaw allows a local attacker to read memory after it has been freed, potentially exposing sensitive information. There is no indication of integrity or availability impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability in Red Hat Enterprise Linux 10 starting from version 10.2.2. Users should apply the latest available updates for the xorg-x11-server and xorg-x11-server-Xwayland packages as described in Red Hat Security Advisory RHSA-2026:26566. No additional mitigation steps are required beyond applying the official patches.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-04T14:55:24.012Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-50263","vendor":"Red Hat"}]
Threat ID: 6a22b79be29bf47b50637ec0
Added to database: 06/05/2026, 11:48:43 UTC
Last enriched: 08/06/2026, 13:46:58 UTC
Last updated: 09/13/2026, 15:18:55 UTC
Views: 269
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.