Skip to main content

Threats Tagged 'cve-2026-56000'

View all threats tagged with 'cve-2026-56000'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-56000

Threats Tagged 'cve-2026-56000'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-56000 is a critical heap use-after-free vulnerability in the X.Org xorg-x11-server and xwayland components before versions 21.2.24 and 24.1.13 respectively. It can be triggered locally by an attacker with an X connection capable of providing GLX commit to the X server. The issue arises from CommonMakeCurrent() referencing potentially reallocated memory. The vulnerability has a CVSS 4.0 score of 9, indicating high severity. No official patch or remediation guidance is currently confirmed.

Join the discussion

Two security vulnerabilities affecting xorg-x11-server-Xwayland in Red Hat Enterprise Linux 10 have been addressed. These include a heap buffer overflow in the glamor Font Atlas component (CVE-2026-55999) and a use-after-free vulnerability in GLX contextTags within CommonMakeCurrent() (CVE-2026-56000). Both issues are rated with high severity by Red Hat Product Security. An update is available to remediate these vulnerabilities.

Join the discussion
0

This update for xwayland fixes the following issues - CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). - CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894).

Join the discussion

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

Join the discussion

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2026-56000
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses