CVE-2026-93523
Public on 2026-10-09
Modified on 2026-10-09
Description
The XI2 passive ungrab path (XIPassiveUngrabDevice) is missing the modifier validation that exists in the grab path and in legacy XI paths. Without checking against AllModifiersMask, a client can supply out-of-range modifier values that lead to an out-of-bounds write when the modifier is used as an index.
An authenticated X client can trigger this by sending an XIPassiveUngrabDevice request with an out-of-range modifier value.
The out-of-bounds write can lead to arbitrary code execution or denial of service.
NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/aa56160fa213d8767e7da0c076b5c8242703313b (xorg-server-21.1.25)
An authenticated X client can trigger this by sending an XIPassiveUngrabDevice request with an out-of-range modifier value.
The out-of-bounds write can lead to arbitrary code execution or denial of service.
NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/aa56160fa213d8767e7da0c076b5c8242703313b (xorg-server-21.1.25)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | tigervnc | Pending Fix | ||
| Amazon Linux 2023 | tigervnc | Pending Fix | ||
| Amazon Linux 2 - Core | wayland | Not Affected | ||
| Amazon Linux 2023 | wayland | Not Affected | ||
| Amazon Linux 2027 Preview | wayland | Not Affected | ||
| Amazon Linux 2023 | xisxwayland | Not Affected | ||
| Amazon Linux 2027 Preview | xisxwayland | Not Affected | ||
| Amazon Linux 2 - Core | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xwayland-run | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |