CVE-2026-33999
TigerVNC vulnerability analysis and mitigation

Overview

CVE-2026-33999 is an integer underflow vulnerability in the X.Org X server's XKB (X Keyboard Extension) compatibility map handling that allows an attacker with local or remote X11 server access to trigger a buffer read overrun. The flaw exists in the XkbSetCompatMap() function, where a previously truncated "compat" buffer leaves unused space that is later reused without correctly updating the count of valid entries, causing internal size/index calculations to underflow. Affected software includes X.Org X server and Xwayland across a wide range of Linux distributions. The vulnerability was reported on March 25, 2026, and publicly disclosed on April 23, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound). The vulnerability occurs in XkbSetCompatMap() when a previously truncated compatibility map buffer is reused without updating the count of valid entries; subsequent XKB requests then perform size/index calculations that can underflow, resulting in a buffer read overrun beyond the intended memory region (Red Hat Bugzilla). An attacker requires low-privileged local access to the X11 server, or can exploit the flaw remotely via X11 forwarding or SSH tunneling, with no user interaction required. The upstream fix is referenced at https://gitlab.freedesktop.org/xorg/xserver/-/commit/b024ae17 (ZDI Advisory).

Impact

Successful exploitation can lead to memory-safety violations, including disclosure of sensitive process memory contents and reading of arbitrary data from the X server's address space, as well as a denial of service through an X server crash. In environments where Xorg runs with elevated privileges (e.g., setuid root), the impact could extend beyond a simple DoS to more severe memory corruption outcomes. The vulnerability affects all systems running vulnerable versions of X.Org X server or Xwayland, including those using TigerVNC and other X11-based remote desktop solutions (Red Hat CVE, GitHub Advisory).

Exploitability

No confirmed working exploit or proof-of-concept code is publicly available; the Zero Day Initiative published an advisory (ZDI-26-333) describing the vulnerability and pointing to the vendor fix, but it contains no exploit code or reproduction steps (ZDI Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.012% (very low probability of exploitation in the next 30 days), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).

Mitigation and workarounds

X.Org has released a fix committed at https://gitlab.freedesktop.org/xorg/xserver/-/commit/b024ae17. Upstream releases Xorg Server 21.1.22 and Xwayland 24.1.10 include the fix (9to5Linux). Red Hat has issued numerous security advisories addressing this CVE across RHEL 6 through 10 and related products (TigerVNC, Xwayland), including RHSA-2026:10739 (RHEL 9), RHSA-2026:11352 (RHEL 10), RHSA-2026:11656 (RHEL 8), and many others (Red Hat Bugzilla). Patches are also available for openSUSE, Slackware, Amazon Linux 2/2023, AlmaLinux, Rocky Linux, Oracle Linux, OpenBSD, and Mageia. As a workaround, restrict local and remote X11 server access to trusted users only, and disable X11 forwarding over SSH where not required.

Community reactions

The release of Xorg Server 21.1.22 and Xwayland 24.1.10 addressing this and related CVEs received coverage from Linux-focused outlets including GamingOnLinux, 9to5Linux, Linuxiac, and LinuxToday, noting that X.Org remains actively maintained with security fixes (GamingOnLinux, 9to5Linux). The vulnerability was also discussed on the oss-security mailing list and noted by the security community on Mastodon. Community sentiment was generally measured, with the primary concern being the broad distribution of affected packages across major Linux distributions rather than immediate exploitation risk.

Additional resources


SourceThis report was generated using AI

Related TigerVNC vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-50264HIGH7.8
  • NixOS logoNixOS
  • xorg-x11-server-Xvfb
NoYesJun 05, 2026
CVE-2026-50261HIGH7.8
  • NixOS logoNixOS
  • tigervnc-selinux
NoYesJun 05, 2026
CVE-2026-50260HIGH7.8
  • NixOS logoNixOS
  • xorg-x11-server-devel
NoYesJun 05, 2026
CVE-2026-50263MEDIUM5.5
  • NixOS logoNixOS
  • tigervnc-x11-server-debuginfo
NoYesJun 05, 2026
CVE-2026-50262MEDIUM5.5
  • NixOS logoNixOS
  • tigervnc-server-module
NoYesJun 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management