QSearchQSearch

CVE-2026-34001

7.8 HIGH

A flaw was found in the X.Org X server

Published: 2026-04-23 · Last updated: 2026-06-08

Severity and scoring

CVSS
7.8 HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-825

Description

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-8854 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache (7.5 HIGH)
  • CVE-2025-61664 A vulnerability in the GRUB2 bootloader has been identified in the normal module (4.9 MEDIUM)
  • CVE-2025-54771 A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader) (4.9 MEDIUM)
  • CVE-2025-54770 A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk (4.9 MEDIUM)
  • CVE-2025-49795 A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions (7.5 HIGH)