
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33999 is an integer underflow vulnerability in the X.Org X server's XKB (X Keyboard Extension) compatibility map handling that allows an attacker with local or remote X11 server access to trigger a buffer read overrun. The flaw exists in the XkbSetCompatMap() function, where a previously truncated "compat" buffer leaves unused space that is later reused without correctly updating the count of valid entries, causing internal size/index calculations to underflow. Affected software includes X.Org X server and Xwayland across a wide range of Linux distributions. The vulnerability was reported on March 25, 2026, and publicly disclosed on April 23, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, GitHub Advisory).
The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound). The vulnerability occurs in XkbSetCompatMap() when a previously truncated compatibility map buffer is reused without updating the count of valid entries; subsequent XKB requests then perform size/index calculations that can underflow, resulting in a buffer read overrun beyond the intended memory region (Red Hat Bugzilla). An attacker requires low-privileged local access to the X11 server, or can exploit the flaw remotely via X11 forwarding or SSH tunneling, with no user interaction required. The upstream fix is referenced at https://gitlab.freedesktop.org/xorg/xserver/-/commit/b024ae17 (ZDI Advisory).
Successful exploitation can lead to memory-safety violations, including disclosure of sensitive process memory contents and reading of arbitrary data from the X server's address space, as well as a denial of service through an X server crash. In environments where Xorg runs with elevated privileges (e.g., setuid root), the impact could extend beyond a simple DoS to more severe memory corruption outcomes. The vulnerability affects all systems running vulnerable versions of X.Org X server or Xwayland, including those using TigerVNC and other X11-based remote desktop solutions (Red Hat CVE, GitHub Advisory).
No confirmed working exploit or proof-of-concept code is publicly available; the Zero Day Initiative published an advisory (ZDI-26-333) describing the vulnerability and pointing to the vendor fix, but it contains no exploit code or reproduction steps (ZDI Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.012% (very low probability of exploitation in the next 30 days), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).
X.Org has released a fix committed at https://gitlab.freedesktop.org/xorg/xserver/-/commit/b024ae17. Upstream releases Xorg Server 21.1.22 and Xwayland 24.1.10 include the fix (9to5Linux). Red Hat has issued numerous security advisories addressing this CVE across RHEL 6 through 10 and related products (TigerVNC, Xwayland), including RHSA-2026:10739 (RHEL 9), RHSA-2026:11352 (RHEL 10), RHSA-2026:11656 (RHEL 8), and many others (Red Hat Bugzilla). Patches are also available for openSUSE, Slackware, Amazon Linux 2/2023, AlmaLinux, Rocky Linux, Oracle Linux, OpenBSD, and Mageia. As a workaround, restrict local and remote X11 server access to trusted users only, and disable X11 forwarding over SSH where not required.
The release of Xorg Server 21.1.22 and Xwayland 24.1.10 addressing this and related CVEs received coverage from Linux-focused outlets including GamingOnLinux, 9to5Linux, Linuxiac, and LinuxToday, noting that X.Org remains actively maintained with security fixes (GamingOnLinux, 9to5Linux). The vulnerability was also discussed on the oss-security mailing list and noted by the security community on Mastodon. Community sentiment was generally measured, with the primary concern being the broad distribution of affected packages across major Linux distributions rather than immediate exploitation risk.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."