Your message dated Wed, 05 Aug 2026 10:36:32 +0000
with message-id <[email protected]>
and subject line Bug#1141703: fixed in xorg-server 2:21.1.24-1
has caused the Debian Bug report #1141703,
regarding xorg-server: CVE-2026-55999 CVE-2026-56000
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1141703: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141703
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: xorg-server
Version: 2:21.1.23-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 2:21.1.16-1

Hi,

The following vulnerabilities were published for xorg-server.

CVE-2026-55999[0]:
| Local attackers with a X connection able to provide PCX fonts to the
| X  server xorg-server before 21.2.24 and xwayland before 24.1.13
| could  cause a heap buffer overflow via SetFont due to missing glyph
| boundary checks.


CVE-2026-56000[1]:
| Local attackers with a X connection able to provide GLX commit to
| the X server xorg-server before 21.2.24 and xwayland before 24.1.13
| could cause a Heap Use After Free, due to CommonMakeCurrent()
| pointing into potentially reallocated memory.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55999
    https://www.cve.org/CVERecord?id=CVE-2026-55999
[1] https://security-tracker.debian.org/tracker/CVE-2026-56000
    https://www.cve.org/CVERecord?id=CVE-2026-56000
[2] https://www.openwall.com/lists/oss-security/2026/07/08/2

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: xorg-server
Source-Version: 2:21.1.24-1
Done: Emilio Pozuelo Monfort <[email protected]>

We believe that the bug you reported is fixed in the latest version of
xorg-server, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emilio Pozuelo Monfort <[email protected]> (supplier of updated xorg-server 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 05 Aug 2026 12:04:38 +0200
Source: xorg-server
Architecture: source
Version: 2:21.1.24-1
Distribution: unstable
Urgency: medium
Maintainer: Debian X Strike Force <[email protected]>
Changed-By: Emilio Pozuelo Monfort <[email protected]>
Closes: 1141703
Changes:
 xorg-server (2:21.1.24-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release.
     -  CVE-2026-55999: glamor Font Atlas Heap Buffer Overflow
     -  CVE-2026-56000: GLX contextTags Use-After-Free in CommonMakeCurrent()
     Closes: #1141703.
Checksums-Sha1:
 4d1bcd1a04a34ad9a14b7001a193c929eb91cf84 4040 xorg-server_21.1.24-1.dsc
 2301d8084a777b942f3d7e3860a506c855986996 9036382 
xorg-server_21.1.24.orig.tar.gz
 8130aaa668b7e2d49859c0b27201b5d3cb59dbb9 178470 xorg-server_21.1.24-1.diff.gz
 3deb538ad45c7289b8e6af0da106c797460265e9 9435 
xorg-server_21.1.24-1_source.buildinfo
Checksums-Sha256:
 03e384de62bdbe4a5830e19f73fa0fdda97f7071f1cdd56ea18e2335613aa0f6 4040 
xorg-server_21.1.24-1.dsc
 d01ccd7ba48ec9d6815aeef5fb408d0c307ab6be21d20ff0b54b11f1c2b8a075 9036382 
xorg-server_21.1.24.orig.tar.gz
 d0c8e5abf7ca569d08b2ecde7f45e4178d28b415113844ce5a0395c10ac6e91a 178470 
xorg-server_21.1.24-1.diff.gz
 b25510af9b80653a1579c67d1be3944c0592b4353495f6b94005503e1a2ec119 9435 
xorg-server_21.1.24-1_source.buildinfo
Files:
 20a7f5bfc808bfbb7cec06996a0d0e50 4040 x11 optional xorg-server_21.1.24-1.dsc
 f6e5b3ae9013a4b926a31d11c5656202 9036382 x11 optional 
xorg-server_21.1.24.orig.tar.gz
 e12e06170600d4e704f61ebc2771c1df 178470 x11 optional 
xorg-server_21.1.24-1.diff.gz
 9a20e6a2ed9444e598f9a4f49aa8f8c8 9435 x11 optional 
xorg-server_21.1.24-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmpzCxEACgkQnUbEiOQ2
gwJBYxAAg4Hs2xJW97KyEZFZJvMHm94XzEGuXcu2wmTLRRfNhSkbLpymp6JzvhKJ
721w6/y8K0BNguB4fdxlfe4SNItooho/4SF7BVqlD4wAMpSQDtB7haNh6m0RrvOO
AwM34zG++V3GeUhaaaDYhgieMSSeayYbJW33DnYr32+TeNWmkHVCTabOhsE5PWlW
si1HOrUqT+1O4CezOts+FdawyVlWtSUcYAMHoPk3MBCbud5OaPngAmLFL+p7zzvK
9uCUXiuhSuBK6in02ND9Y2SyN8mNw+HWco+bOtp26VdGf9ks4u1EJVNhrcrmZzKC
u5TEBssTK+PUf1S3bCLiOBgZHwdGDAq9e5AMIoVeIp/wj8m3SOLxmbsXRReiDhsW
LQRiRy5oNPAjCGhJU7qGLRSu01pRZX2at5NyK4iPl72TnQEGQOl1ZZqe+Y/AaqBr
B3f9FjZEPtZpTaDSerhnXWU+Oz77N5+FQeUitYjAXHx7eQzArLId62Pl4MtFkOo1
ZzGjfAyOaG4JDuk4Io6uDnndDwjjzN9MJDJzT02AJBtN5BGItWaPiss0nHqoIYcx
nUmi9+9ZTSKkmxd5CNqtq2EE69bdd7kbGYuLQSBDejYKurkDfTdABjKMXTaFaNnT
PLh1rKNKHNCzKyidLdxHUf1gh3QtsGlAGdLYx2eOnOtwc2PvYXk=
=wwW2
-----END PGP SIGNATURE-----

Attachment: pgp6YoZLIfCAS.pgp
Description: PGP signature


--- End Message ---

Reply via email to