CVE-2026-93521
Public on 2026-10-09
Modified on 2026-10-09
Description
In RRChangeProviderProperty() with PrependMode, new_value.size is set to len instead of total_len. Additionally, the old_data offset calculation uses prop_value->size instead of len for the memcpy of existing data. This causes a heap buffer overflow when prepending property data, as the buffer is undersized and the copy offset is incorrect.
This mirrors a bug pattern that was previously fixed in RRChangeOutputProperty but was not applied to the provider property path.
An authenticated X client can trigger this by sending RandR ChangeProviderProperty requests with PrependMode on a system with RandR providers (standard on modern GPUs).
The heap buffer overflow can lead to arbitrary code execution or denial of service.
Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/5dc9efd5a199
This mirrors a bug pattern that was previously fixed in RRChangeOutputProperty but was not applied to the provider property path.
An authenticated X client can trigger this by sending RandR ChangeProviderProperty requests with PrependMode on a system with RandR providers (standard on modern GPUs).
The heap buffer overflow can lead to arbitrary code execution or denial of service.
Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/5dc9efd5a199
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | tigervnc | Pending Fix | ||
| Amazon Linux 2023 | tigervnc | Pending Fix | ||
| Amazon Linux 2 - Core | wayland | Not Affected | ||
| Amazon Linux 2023 | wayland | Not Affected | ||
| Amazon Linux 2027 Preview | wayland | Not Affected | ||
| Amazon Linux 2023 | xisxwayland | Not Affected | ||
| Amazon Linux 2027 Preview | xisxwayland | Not Affected | ||
| Amazon Linux 2 - Core | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xwayland-run | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |