CVE-2026-33999: Red Hat Enterprise Linux 10
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:24.1.5-6.el10_1 (fixed in 0:24.1.5-6.el10_1); before 0:24.1.9-4.el10_2 (fixed in 0:24.1.9-4.el10_2)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:24.1.5-6.el10_0 (fixed in 0:24.1.5-6.el10_0)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 6 Extended Lifecycle Support - Extension: before 0:1.1.0-25.el6_10.16 (fixed in 0:1.1.0-25.el6_10.16)
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:1.20.4-34.el7_9 (fixed in 0:1.20.4-34.el7_9); before 0:1.8.0-36.el7_9.4 (fixed in 0:1.8.0-36.el7_9.4)
- Red Hat Red Hat Enterprise Linux 8: before 0:21.1.3-20.el8_10 (fixed in 0:21.1.3-20.el8_10); before 0:1.20.11-28.el8_10 (fixed in 0:1.20.11-28.el8_10); before 0:1.15.0-9.el8_10 (fixed in 0:1.15.0-9.el8_10)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:1.20.10-4.el8_4 (fixed in 0:1.20.10-4.el8_4); before 0:1.11.0-8.el8_4.15 (fixed in 0:1.11.0-8.el8_4.15)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:1.20.10-4.el8_4 (fixed in 0:1.20.10-4.el8_4); before 0:1.11.0-8.el8_4.15 (fixed in 0:1.11.0-8.el8_4.15)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:21.1.3-2.el8_6.6 (fixed in 0:21.1.3-2.el8_6.6); before 0:1.20.11-7.el8_6 (fixed in 0:1.20.11-7.el8_6); before 0:1.12.0-6.el8_6.17 (fixed in 0:1.12.0-6.el8_6.17)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:1.12.0-6.el8_6.17 (fixed in 0:1.12.0-6.el8_6.17)
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:21.1.3-2.el8_6.6 (fixed in 0:21.1.3-2.el8_6.6); before 0:1.20.11-7.el8_6 (fixed in 0:1.20.11-7.el8_6)
- Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:21.1.3-2.el8_6.6 (fixed in 0:21.1.3-2.el8_6.6); before 0:1.20.11-7.el8_6 (fixed in 0:1.20.11-7.el8_6)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:21.1.3-13.el8_8 (fixed in 0:21.1.3-13.el8_8); before 0:1.20.11-18.el8_8 (fixed in 0:1.20.11-18.el8_8); before 0:1.12.0-15.el8_8.17 (fixed in 0:1.12.0-15.el8_8.17)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:21.1.3-13.el8_8 (fixed in 0:21.1.3-13.el8_8); before 0:1.20.11-18.el8_8 (fixed in 0:1.20.11-18.el8_8); before 0:1.12.0-15.el8_8.17 (fixed in 0:1.12.0-15.el8_8.17)
- Red Hat Red Hat Enterprise Linux 9: before 0:1.15.0-6.el9_7.1 (fixed in 0:1.15.0-6.el9_7.1); before 0:23.2.7-6.el9_7 (fixed in 0:23.2.7-6.el9_7); before 0:1.20.11-33.el9_7 (fixed in 0:1.20.11-33.el9_7); before 0:1.15.0-7.el9_8.1 (fixed in 0:1.15.0-7.el9_8.1); before 0:1.20.11-34.el9_8 (fixed in 0:1.20.11-34.el9_8); before 0:24.1.9-4.el9_8 (fixed in 0:24.1.9-4.el9_8)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:21.1.3-5.el9_0 (fixed in 0:21.1.3-5.el9_0); before 0:1.20.11-13.el9_0 (fixed in 0:1.20.11-13.el9_0); before 0:1.11.0-22.el9_0.17 (fixed in 0:1.11.0-22.el9_0.17)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:21.1.3-10.el9_2 (fixed in 0:21.1.3-10.el9_2); before 0:1.20.11-20.el9_2 (fixed in 0:1.20.11-20.el9_2); before 0:1.12.0-14.el9_2.14 (fixed in 0:1.12.0-14.el9_2.14)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:1.20.11-28.el9_4 (fixed in 0:1.20.11-28.el9_4); before 0:22.1.9-8.el9_4 (fixed in 0:22.1.9-8.el9_4); before 0:1.13.1-8.el9_4.9 (fixed in 0:1.13.1-8.el9_4.9)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:1.20.11-33.el9_6 (fixed in 0:1.20.11-33.el9_6); before 0:23.2.7-6.el9_6 (fixed in 0:23.2.7-6.el9_6); before 0:1.14.1-10.el9_6 (fixed in 0:1.14.1-10.el9_6)
Published 2026-04-23. Last modified 2026-07-15.