CVE-2026-93515
Public on 2026-10-09
Modified on 2026-10-09
Description
Present_clear_window_notifies() does not unlink notify entries from the per-window list before freeing window_priv. When the window is subsequently destroyed or reused, the stale list entries are traversed, resulting in a use-after-free.
An authenticated X client can trigger this by creating cross-window Present notifies and then destroying the target window. Both the Present and SYNC extensions must be enabled (they are by default).
The use-after-free can lead to denial of service (crash) or potentially information disclosure.
NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/a469f98bcfab50dab607ff5ac24037632b0079a3 (xorg-server-21.1.25)
An authenticated X client can trigger this by creating cross-window Present notifies and then destroying the target window. Both the Present and SYNC extensions must be enabled (they are by default).
The use-after-free can lead to denial of service (crash) or potentially information disclosure.
NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/a469f98bcfab50dab607ff5ac24037632b0079a3 (xorg-server-21.1.25)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | tigervnc | Pending Fix | ||
| Amazon Linux 2023 | tigervnc | Pending Fix | ||
| Amazon Linux 2 - Core | wayland | Not Affected | ||
| Amazon Linux 2023 | wayland | Not Affected | ||
| Amazon Linux 2027 Preview | wayland | Not Affected | ||
| Amazon Linux 2023 | xisxwayland | Not Affected | ||
| Amazon Linux 2027 Preview | xisxwayland | Not Affected | ||
| Amazon Linux 2 - Core | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xwayland-run | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 6.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H |