CVE detail
CVE-2026-50256
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
35 source links · newest first
y to respond without out-of-cycle patches. At time of writing, Microsoft has provided mitigation advice and patches for CVE-2026-33825 , CVE-2026-45585 , CVE-2026-45498 , and CVE-2026-41091 , leaving only two elevation of privilege vulnerabilities unpatched, known as MiniPlasma and GreenPlasma. However, a recent blog post by Nightmare Eclipse with the
vendorwww.rapid7.comJun 9, 2026, 9:04 PMInformation published.
vendormsrc.microsoft.comJun 9, 2026, 8:02 AM- https://access.redhat.com/errata/RHSA-2026:46473access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:46392access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:46385access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:46460access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:46456access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:46382access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:46377access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:38810access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50256.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 5, 2026, 12:16 PM - https://redhat.atlassian.net/browse/PSIRTSUPT-16950redhat.atlassian.net
No excerpt available.
Permissions Requiredredhat.atlassian.netJun 5, 2026, 12:16 PM No excerpt available.
Vendor Advisorylists.x.orgJun 5, 2026, 12:16 PM- https://gitlab.freedesktop.org/xorg/xserver/-/commit/bb5158f962dc935e58ef8b4b5fcb31be201a6e07gitlab.freedesktop.org
No excerpt available.
Exploitgitlab.freedesktop.orgJun 5, 2026, 12:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2485380bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/security/cve/CVE-2026-50256access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:38502access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36798access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36792access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36791access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36768access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36634access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36633access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36632access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36087access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36086access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36085access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:36083access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:29844access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:28923access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:26709access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:26610access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:26590access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:26566access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:26562access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 5, 2026, 12:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-50259CVSS 7.8 · High
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. Th…
- CVE-2026-50258CVSS 7.8 · High
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes…
- CVE-2025-26595CVSS 7.8 · High
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to…
- CVE-2026-50264CVSS 7.8 · High
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments a…
- CVE-2026-50263CVSS 5.5 · Medium
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing…
- CVE-2026-50262CVSS 5.5 · Medium
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number…