X.Org server patches 12 flaws, nine allow code execution
X.Org has fixed 12 security vulnerabilities in the X server and Xwayland. Nine of them can lead to arbitrary code execution. The other three can crash the server or expose information.
The fixes ship in xorg-server 21.1.25 and xwayland-24.1.14. The X server is the display server that has long handled graphical output on Linux and other Unix-like desktops. Xwayland is the compatibility layer that lets X applications run on Wayland-based desktops. Because of this, the affected code is present on many systems, often without users noticing it.
Who can trigger the bugs
For ten of the 12 vulnerabilities, the advisory says the flaw can be triggered by an authenticated X client. In plain terms, this is a program that the server already accepts a connection from. The entries for CVE-2026-93524 and CVE-2026-93536 do not state that condition.
Eleven of the 12 issues affect both the X server and Xwayland. The exception is CVE-2026-93522, a heap buffer overflow in the CopyArea code of Glamor, which is used on GPU-accelerated systems. That flaw affects only Xwayland.
A familiar set of memory bugs
The list is dominated by memory safety problems:
- seven buffer overflows or out-of-bounds writes
- three use-after-free bugs, where the server keeps using memory it has already released
- one double free
- one out-of-bounds read
Two of the flaws depend on X extensions that the advisory describes as enabled by default. CVE-2026-93515 needs the Present and SYNC extensions. CVE-2026-93519 requires XFIXES and XTEST, as well as more than 100 active pointer barriers.
Earlier fixes left gaps
Two of the new patches complete work that was started before. CVE-2026-93520 is the result of an incomplete fix in commit a3171732d.
CVE-2026-93521 repeats a bug pattern that had already been fixed in RRChangeOutputProperty. That earlier repair covered the RandR output path, but the provider path was left untouched, so the same weakness remained in a different part of the code.
This kind of issue is not unusual in large, old codebases. When a bug is fixed in one function, similar code elsewhere can keep the same mistake until someone goes looking for it.
What to check
Admins and users who run the X server or Xwayland should compare their installed versions with 21.1.25 and 24.1.14. Systems on older versions remain exposed to the flaws described in the advisory.
Each CVE entry links to its fix commit on freedesktop.org GitLab. This allows administrators, package maintainers and security teams to review the exact code changes and check whether their builds include them.
For most desktop users, the updated packages will arrive through their operating system's normal update channel. Those who build the X server or Xwayland themselves, or who maintain their own packages, will need to pull in the new releases or the individual fix commits.
Our Take
The good news here is that ten of the 12 bugs require an authenticated X client, which limits remote attacks. The less comforting part is that the X server traditionally trusts its clients heavily. On shared machines, remote desktop setups or systems where untrusted applications run, a malicious or compromised program could be enough to reach these flaws. Nine of them carry code execution potential, so it is worth treating this release as more than routine maintenance.
The two "finishing" fixes are arguably the most telling detail. They suggest that patching one instance of a bug pattern does not always clear the whole codebase, a lesson that keeps coming up as vulnerability disclosures continue to climb.
It is worth watching how quickly Linux distributions ship the new versions, and whether further variants turn up in related code. As with other large batches such as the recent Chrome and Firefox updates, the main risk is that systems simply stay unpatched.
