Posts tagged with “x.org”

X.Org server patches 12 flaws, nine allow code execution

X.Org has fixed 12 security vulnerabilities in the X server and Xwayland. Nine of them can lead to arbitrary code execution. The other three can crash the server or expose information.

The fixes ship in xorg-server 21.1.25 and xwayland-24.1.14. The X server is the display server that has long handled graphical output on Linux and other Unix-like desktops. Xwayland is the compatibility layer that lets X applications run on Wayland-based desktops. Because of this, the affected code is present on many systems, often without users noticing it.

Who can trigger the bugs

For ten of the 12 vulnerabilities, the advisory says the flaw can be triggered by an authenticated X client. In plain terms, this is a program that the server already accepts a connection from. The entries for CVE-2026-93524 and CVE-2026-93536 do not state that condition.

Read More