Integer Underflow (Wrap or Wraparound) Affecting xorg-server package, versions [,21.1.22)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.38% (30th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-XORGSERVER-16304806
  • published27 Apr 2026
  • disclosed23 Apr 2026
  • creditJan-Niklas Sohn

Introduced: 23 Apr 2026

CVE-2026-33999  (opens in a new tab)
CWE-191  (opens in a new tab)

How to fix?

Upgrade xorg-server to version 21.1.22 or higher.

Overview

Affected versions of this package are vulnerable to Integer Underflow (Wrap or Wraparound) via the XkbSetCompatMap() function in the XKB compatibility map handling process. An attacker can cause memory-safety violations and potentially disrupt system availability by triggering a buffer read overrun through local or remote access to the X11 server.

Workaround

This vulnerability can be mitigated by restricting access to the X11 server. For remote access, disable X11 forwarding in SSH configurations by editing /etc/ssh/sshd_config and setting X11Forwarding no, then restarting the sshd service using systemctl restart sshd.

CVSS Base Scores

version 4.0
version 3.1