CVE-2026-93536
Public on 2026-10-09
Modified on 2026-10-09
Description
GestureBuildSprite() copies raw WindowPtr values into the gesture sprite trace via CopySprite() without any reference counting or lifetime management. WindowGone() only repairs touch sprite traces when a window is destroyed -- gesture sprite traces are never checked or cleaned. This leaves stale WindowPtr references in gesture sprites.
When DeliverOneGestureEvent() later dereferences the stale WindowPtr via DeepestSpriteWin(&gi->sprite)->drawable.id, it produces a use-after-free. The freed 4 bytes (drawable.id) can be read back, potentially leaking information about the contents of the freed memory region.
NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/4c9c345d2a10baf956fdefa83bb88681f7c840cf (xorg-server-21.1.25)
When DeliverOneGestureEvent() later dereferences the stale WindowPtr via DeepestSpriteWin(&gi->sprite)->drawable.id, it produces a use-after-free. The freed 4 bytes (drawable.id) can be read back, potentially leaking information about the contents of the freed memory region.
NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/4c9c345d2a10baf956fdefa83bb88681f7c840cf (xorg-server-21.1.25)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | wayland | Not Affected | ||
| Amazon Linux 2023 | wayland | Not Affected | ||
| Amazon Linux 2027 Preview | wayland | Not Affected | ||
| Amazon Linux 2023 | xisxwayland | Not Affected | ||
| Amazon Linux 2027 Preview | xisxwayland | Not Affected | ||
| Amazon Linux 2 - Core | xorg-x11-server | Not Affected | ||
| Amazon Linux 2023 | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xwayland-run | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.3 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H |