X.Org Patches Twelve CVEs in X Server and Xwayland Security Update

Published by

X.Org has released twelve security patches addressing vulnerabilities in xorg-server 21.1.25, the standalone 26.1.0 release candidate 26.0.99.903, and xwayland 24.1.14. The vulnerabilities include serious issues such as double frees, use-after-frees, and heap overflows, which can be exploited by compromised local applications to take control of the session or access sensitive information. Users on various operating systems, including Debian, Ubuntu, and Windows, are advised to update their systems promptly, particularly those operating multi-user hardware. The release highlights ongoing security improvements in the X server, reinforcing the need for regular updates to mitigate potential risks



X.Org Patches Twelve CVEs in X Server and Xwayland Security Update

X.Org released twelve security fixes today across three simultaneous packages: xorg-server 21.1.25, the standalone 26.1.0 release candidate 26.0.99.903, and xwayland 24.1.14. The vulnerabilities, which includes double frees, use-after-frees, heap overflows, numeric truncation, and out-of-bounds reads and spana the XKB, GLX, RandR, XFixes, XInput2, Present, and glamor extensions. Most can be triggered by an authenticated local X client, meaning a compromised app on your machine could seize the session or leak memory. Users on Debian, Ubuntu, Arch, XQuartz, or Windows X servers should update as soon as the packages propagate, with multi-user hosts treated as highest priority.

X.Org Patches Twelve CVEs in X Server and Xwayland Security Update @ Linux Compatible