Update X.Org Server 21.1.24, xwayland 24.1.13, and libXfont2 2.0.8 addressing vulnerabilities

Corrective releases of X.Org Server 21.1.24 and the DDX component (Device-Dependent X) xwayland 24.1.13 have been published. These updates enable the launch of X.Org Server for running X11 applications in Wayland-based environments. The new versions address two vulnerabilities that could potentially be exploited for privilege escalation in systems where the X server runs with root rights, as well as for remote code execution in configurations where session redirection via SSH is used for access.

Fixed vulnerabilities:

  • CVE-2026-55999 — Buffer overflow in the implementation of 2D acceleration architecture Glamor affecting the glamor_font_get() function, which generates a font texture atlas by rendering each glyph into a shared buffer. The issue arises because the buffer size was determined based on the parameters specified in the font, while individual metrics for each glyph were used when creating data to be copied into the buffer. To exploit this vulnerability, an attacker could craft a specially formatted PCF file with incorrect glyph metrics that exceed the allocated memory size. The overflow occurs on systems using the glamor backend (Xorg with modesetting driver and Xwayland) when rendering text with the problematic font.
  • CVE-2026-56000 — Use-after-free in the CommonMakeCurrent() function when handling GLX contextTags. The problem arises because when using the realloc() function, the data of the array cl->contextTags was moved to a new buffer, but a pointer referencing the old buffer remained in use. To initiate the buffer relocation, a client could occupy all the allocated elements of the GLX context's array and then create an additional context.

Additionally, the release of the libXfont library version 2.0.8, used in the X server, has been noted. The update fixes three vulnerabilities (CVE-2026-56001, CVE-2026-56002, CVE-2026-56003) that result in buffer overflow when parsing specially crafted fonts in PCF format.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster