The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 87.0%