Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2656 articles · 130317 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-33999PATCHED
Red Hat · Red Hat Enterprise Linux 10

Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling

Description

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 10—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
red hatred hat enterprise linuxmitre_affected90%

References

  • https://access.redhat.com/errata/RHSA-2026:10739(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:11352(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:11369(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-33999(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2451106(issue-tracking, x_refsource_REDHAT)

Related News (2 articles)

Tier A
Microsoft MSRC5h ago
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-33999 | X.org X Server XKB Compatibility Map integer underflow
→ No new info (linked only)
CVSS 3.17.8 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
0:1.15.0-6.el9_7.1
CWECWE-191
PublishedApr 23, 2026
Last enriched5d ago
Trending Score36
Source articles2
Independent2
Info Completeness6/14
Missing: versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-34001
Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
Trending: 36
NONECVE-2026-34003
Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
Trending: 36
NONECVE-2026-7309
Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection
Trending: 31
HIGHPRE-CVE
Multiple Vulnerabilities in Red Hat Products Allow Remote Code Execution, File Manipulation, and Denial of Service
Trending: 24
MEDIUMPRE-CVE
Multiple Denial of Service Vulnerabilities in Red Hat Virtualization
Trending: 23

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 23, 2026
Discovered by ZDM
Apr 23, 2026
Patch Available
Apr 28, 2026