CVE-2026-50263

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.

Credits

Upstream acknowledges Anonymous (Trend Micro Zero Day Initiative) as the original reporter.

References