CVE-2026-93522

Public on 2026-10-09
Modified on 2026-10-09
Description
In glamor's CopyArea CPU-to-FBO path, the temporary buffer (tmp_bits) is sized based on the destination height but is indexed using source coordinates. When the source region is taller than the destination, writes overflow the allocated buffer.
An authenticated X client can trigger this by performing a CopyArea operation between drawables with mismatched depth (depth-24 to depth-32 or vice versa) where the source is taller than the destination, on a system using glamor/GPU acceleration.

The heap buffer overflow can lead to arbitrary code execution or denial of service.
This issue does not affect xorg-server-21.1.x
Fixed in: xwayland-24.1.14
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/ad26c26bf795
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 tigervnc Not Affected
Amazon Linux 2 - Core wayland Not Affected
Amazon Linux 2023 wayland Not Affected
Amazon Linux 2027 Preview wayland Not Affected
Amazon Linux 2023 xisxwayland Not Affected
Amazon Linux 2027 Preview xisxwayland Not Affected
Amazon Linux 2 - Core xorg-x11-server Not Affected
Amazon Linux 2023 xorg-x11-server Not Affected
Amazon Linux 2023 xorg-x11-server-Xwayland Pending Fix
Amazon Linux 2027 Preview xorg-x11-server-Xwayland Pending Fix
Amazon Linux 2027 Preview xwayland-run Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H