EIP-2026-103040

PRE-CVE

XFree86 4.2 - 'XLOCALEDIR' Local Buffer Overflow (2)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103040. PoCs published by Guilecool & deka.

AI-analyzed exploit summary This exploit leverages a buffer overflow in XFree86 utilities via the XLOCALEDIR environment variable to achieve local privilege escalation. It overwrites the return address with a hardcoded stack address and executes shellcode to spawn a root shell.

Description

XFree86 4.2 - 'XLOCALEDIR' Local Buffer Overflow (2)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Guilecool & deka · clocallinux
https://www.exploit-db.com/exploits/22321

This exploit leverages a buffer overflow in XFree86 utilities via the XLOCALEDIR environment variable to achieve local privilege escalation. It overwrites the return address with a hardcoded stack address and executes shellcode to spawn a root shell.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: XFree86 (xscreensaver utility)
No auth needed
Prerequisites: Local access to the system · XFree86 must be running · XLOCALEDIR environment variable must be unset or controllable
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026