X.Org Server and XWayland have received urgent security updates.

X.Org developers have released xorg-server 21.1.23 and XWayland 24.1.12, addressing nine vulnerabilities in X.Org X Server and XWayland. The fixes were published on June 2, 2026; source archives xorg-server-21.1.23 and xwayland-24.1.12 are already available in the official X.Org catalog.

The issues affect both the classic X.Org Server and XWayland — the component that allows X11 applications to run within Wayland sessions. Therefore, the update is important not only for users of a full X11 session but also for those who have already switched to Wayland but continue to run old X11 applications and games.

At the time of disclosure, CVEs had not yet been assigned, so the vulnerabilities were identified using ZDI-CAN identifiers and problem descriptions. Eight of the vulnerabilities were reported by an anonymous researcher through the TrendAI Zero Day Initiative, and one was discovered by Red Hat developer and long-time X.Org participant Peter Hutterer.

What has been fixed

  • Stack buffer overflow when handling font alias.
    The error occurred due to mismatched constraints in the X server and libXfont2: server it allocated a buffer of 256 bytes, while the target alias name could reach 1024 bytes. A specially crafted font alias with a length of 257 to 1023 bytes could lead to a write beyond the buffer.

  • Use-after-free in XSYNC miSyncDestroyFence().
    A client could create multiple fence triggers, wait for them to be triggered, and then destroy the fence through a second connection. This resulted in accessing already freed memory and potentially calling a freed function pointer.

  • Stack buffer overflows in XKB Key Types.
    In the CheckKeyTypes() key type checking code, there were insufficient restrictions on non-standard key types according to XkbMaxShiftLevel. As a result, a client could specify an excessive number of switch levels, leading to multiple stack overflows. It is also noted that this problem is related to an incomplete fix of a previous vulnerability CVE-2025-26597.

  • Stack buffer overflow in XKB SetMap Request.
    In the _XkbSetMapChecks() function, a fixed array mapWidths[256] was used, indexed by the key type number. With controlled client offset, a helper function could write data beyond this array.

  • Use-after-free in XSYNC FreeCounter().
    The vulnerability manifested when working with multiple SyncCounters: one client could expect triggers to be activated, while a second connection could destroy the corresponding counters, leading to access to freed memory.

  • Use-after-free in XSYNC SyncChangeCounter().
    A similar scenario involved modifying the counters: when multiple connections worked simultaneously, a client could end up accessing an already freed SyncCounter while its state was being changed.

  • Buffer overflow in GLX ChangeDrawableAttributes.
    In the handler __glXDisp_ChangeDrawableAttributes(), there was an incorrect request size check. This allowed reading or writing a client-controlled number of bytes beyond the request buffer. Reading could lead to information disclosure, while writing could result in crashes server, and when running the X server as root, it theoretically opened a path to privilege escalation.

  • Use-after-free and information leakage in CreateSaverWindow.
    The client could modify window attributes and force the screensaver to activate, after which the server accessed already freed data. This scenario is described in the bulletin as potentially leading to information disclosure.

  • Heap overflow in DRI2 DRIGetBuffers / DRIGetBuffersWithFormat.
    The error occurred when requesting multiple DRI2BufferBackLeft and one DRI2BufferFrontLeft. Such a request could lead to writing beyond the allocated memory area in the heap. This is the only one of nine issues found not through TrendAI ZDI, but by Peter Hatterer.

No individual new features were announced in this release: 21.1.23 and 24.1.12 are primarily security patch releases. Users and maintainers of distributions are advised to update both packages: xorg-server for classic X11 and xwayland for X11 application compatibility in Wayland sessions.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster