X.Org Server: 12 Critical Vulnerabilities Patched – Update Now!

www.news4hackers.com-x-org-server-12-critical-vulnerabilities-patched-update-now--x-org-server-12-critical-vulnerabilities-patched-update-now-

Check your X.Org server version as multiple security flaws have been resolved in recent updates.

Key Details of the Security Update

The X.Org project addressed 12 vulnerabilities across the X server and Xwayland components, with fixes included in xorg-server 21.1.25 and xwayland-24.1.14. Nine of these issues could enable arbitrary code execution, while three pose risks of server crashes or data exposure.

Vulnerability Overview

Ten of the vulnerabilities require an authenticated X client to exploit, meaning the attacker must interact with a program already connected to the server. Two specific flaws, CVE-2026-93524 and CVE-2026-93536, do not have this prerequisite.

CVE Details

Eleven of the 12 flaws impact both the X server and Xwayland, whereas CVE-2026-93522, a heap buffer overflow in Glamor’s CopyArea code on GPU-accelerated systems, is limited to Xwayland. The vulnerabilities include seven buffer overflows or out-of-bounds write errors, three use-after-free conditions, one double free issue, and a single out-of-bounds read.

Two of the flaws rely on extensions enabled by default: CVE-2026-93515 requires the Present and SYNC extensions, while CVE-2026-93519 depends on XFIXES and XTEST along with over 100 active pointer barriers.

Fixes and Prior Work

Two fixes build on prior work, with CVE-2026-93520 stemming from an incomplete resolution in commit a3171732d and CVE-2026-93521 repeating a pattern addressed in RRChangeOutputProperty. The RandR output path received a fix, but the provider path remained vulnerable.

Recommendations for Users

Users running the X server or Xwayland should verify their installed versions against 21.1.25 and 24.1.14. Each CVE entry provides links to its corresponding fix in the freedesktop.org GitLab repository. The advisory highlights the importance of updating to the latest releases to mitigate risks associated with these flaws.



About Author

en_USEnglish