CVE-2026-93522
Public on 2026-10-09
Modified on 2026-10-09
Description
In glamor's CopyArea CPU-to-FBO path, the temporary buffer (tmp_bits) is sized based on the destination height but is indexed using source coordinates. When the source region is taller than the destination, writes overflow the allocated buffer.
An authenticated X client can trigger this by performing a CopyArea operation between drawables with mismatched depth (depth-24 to depth-32 or vice versa) where the source is taller than the destination, on a system using glamor/GPU acceleration.
The heap buffer overflow can lead to arbitrary code execution or denial of service.
This issue does not affect xorg-server-21.1.x
Fixed in: xwayland-24.1.14
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/ad26c26bf795
An authenticated X client can trigger this by performing a CopyArea operation between drawables with mismatched depth (depth-24 to depth-32 or vice versa) where the source is taller than the destination, on a system using glamor/GPU acceleration.
The heap buffer overflow can lead to arbitrary code execution or denial of service.
This issue does not affect xorg-server-21.1.x
Fixed in: xwayland-24.1.14
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/ad26c26bf795
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2023 | tigervnc | Not Affected | ||
| Amazon Linux 2 - Core | wayland | Not Affected | ||
| Amazon Linux 2023 | wayland | Not Affected | ||
| Amazon Linux 2027 Preview | wayland | Not Affected | ||
| Amazon Linux 2023 | xisxwayland | Not Affected | ||
| Amazon Linux 2027 Preview | xisxwayland | Not Affected | ||
| Amazon Linux 2 - Core | xorg-x11-server | Not Affected | ||
| Amazon Linux 2023 | xorg-x11-server | Not Affected | ||
| Amazon Linux 2023 | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xwayland-run | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |