-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4738-1                [email protected]
https://www.debian.org/lts/security/                     Arnaud Rebillout
August 13, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : xorg-server
Version        : 2:1.20.11-1+deb11u18
CVE ID         : CVE-2022-49737 CVE-2026-33999 CVE-2026-34000 CVE-2026-34001 
                 CVE-2026-34002 CVE-2026-34003 CVE-2026-50256 CVE-2026-50257 
                 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 
                 CVE-2026-50262 CVE-2026-50263 CVE-2026-50264
Debian Bug     : 1081338 1138680

Several vulnerabilities were discovered in the Xorg X server, which may
result in privilege escalation if the X server is running privileged.

CVE-2022-49737

    In X.Org X server 20.11 through 21.1.16, when a client application
    uses easystroke for mouse gestures, the main thread modifies various
    data structures used by the input thread without acquiring a lock,
    aka a race condition. In particular, AttachDevice in dix/devices.c
    does not acquire an input lock.

CVE-2026-33999

    A flaw was found in the X.Org X server. This integer underflow
    vulnerability, specifically in the XKB compatibility map handling,
    allows an attacker with local or remote X11 server access to trigger
    a buffer read overrun. This can lead to memory-safety violations and
    potentially a denial of service (DoS) or other severe impacts.

CVE-2026-34000

    A flaw was found in the X.Org X server. This out-of-bounds read
    vulnerability in the XKB geometry processing, specifically within the
    `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an
    attacker to read uninitialized or out-of-bounds memory. An attacker
    with a connection to the X11 server, either locally or remotely, can
    exploit this without user interaction. This could lead to the
    disclosure of memory contents or cause a denial of service by
    crashing the server.  Source        

CVE-2026-34001

    A flaw was found in the X.Org X server. This use-after-free
    vulnerability occurs in the XSYNC fence triggering logic,
    specifically within the miSyncTriggerFence() function. An attacker
    with access to the X11 server can exploit this without user
    interaction, leading to a server crash and potentially enabling
    memory corruption. This could result in a denial of service or
    further compromise of the system.

CVE-2026-34002

    A flaw was found in the X.Org X server. This vulnerability, an
    out-of-bounds read, affects the XKB (X Keyboard Extension) modifier
    map handling. An attacker with access to the X11 server can exploit
    this by sending a malformed request, which causes the server to read
    beyond its intended memory boundaries. This can lead to the exposure
    of sensitive information or cause the server to crash, resulting in a
    denial of service.

CVE-2026-34003

    A flaw was found in the X.Org X server's XKB key types request
    validation. A local attacker could send a specially crafted request
    to the X server, leading to an out-of-bounds memory access
    vulnerability. This could result in the disclosure of sensitive
    information or cause the server to crash, leading to a Denial of
    Service (DoS). In certain configurations, higher impact outcomes may
    be possible.

CVE-2026-50256

    A stack-based buffer overflow flaw was found in the X.Org X server
    and Xwayland. A mismatch between the X server and the libXfont2
    library's maximum font name length can cause a stack buffer overflow
    during font alias resolution. The server allocates a 256 byte stack
    buffer but libXfont2's alias target name length is 1024 bytes. A font
    alias name between 257 and 1023 bytes causes the X server to copy
    that name into the undersized stack buffer without further checks.
    This may be used to crash the server, or for privilege escalation if
    the X server runs as root.

CVE-2026-50257

    A use-after-free flaw was found in the X.Org X server and Xwayland in
    miSyncDestroyFence(). A client that sets up multiple fence triggers
    can trigger a use-after-free function pointer call. An attacker would
    connect to the X server to set up a fence and await that fence, then
    a second X connection destroys the fence, causing the use-after-free.
    This may be used to crash the server, or for privilege escalation if
    the X server runs as root.

CVE-2026-50258

    A stack-based buffer overflow flaw was found in the X.Org X server
    and Xwayland. The X server has multiple stack buffers sized
    XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not
    verify or clamp non-canonical key types to XkbMaxShiftLevel. A client
    can change key types to excessive shift levels and trigger stack
    overflows. This is caused by an incomplete fix of CVE-2025-26597.
    This may be used to crash the server, or for privilege escalation if
    the X server runs as root.

CVE-2026-50259

    A stack-based buffer overflow flaw was found in the X.Org X server
    and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer
    mapWidths[256] indexed by key type index. The helper function
    CheckKeyTypes() writes to this buffer at a client-controlled offset,
    allowing a stack buffer overflow. This may be used to crash the
    server, or for privilege escalation if the X server runs as root.

CVE-2026-50260

    A use-after-free flaw was found in the X.Org X server and Xwayland in
    FreeCounter(). A client that sets up multiple SyncCounters and awaits
    on those triggers can trigger a use-after-free when destroying those
    counters via a second client connection. This may be used to crash
    the server, or for privilege escalation if the X server runs as root.

CVE-2026-50261

    A use-after-free flaw was found in the X.Org X server and Xwayland in
    SyncChangeCounter(). A client that sets up multiple SyncCounters can
    trigger a use-after-free when destroying those counters via a second
    client connection while changing those counters. This may be used to
    crash the server, or for privilege escalation if the X server runs as
    root.

CVE-2026-50262

    An out-of-bounds read flaw was found in the X.Org X server and
    Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size
    validation check can read a client-controlled number of bytes,
    exceeding the request buffer, leading to information disclosure. A
    write path also exists but requires byte-swapped clients which is
    disabled by default.

CVE-2026-50263

    A use-after-free flaw was found in the X.Org X server and Xwayland in
    CreateSaverWindow(). A client can trigger a use-after-free read after
    changing window attributes and forcing the screen saver, leading to
    information disclosure.

CVE-2026-50264

    An out-of-bounds write flaw was found in the X.Org X server and
    Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that
    requests multiple DRI2BufferBackLeft attachments and one
    DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may
    be used to crash the server, or for privilege escalation if the X
    server runs as root.

For Debian 12 bullseye, these problems have been fixed in version
2:1.20.11-1+deb11u18.

We recommend that you upgrade your xorg-server packages.

For the detailed security status of xorg-server please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/xorg-server

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE0Kl7ndbut+9n4bYs5yXoeRRgAhYFAmp9T7EACgkQ5yXoeRRg
AhYP9Q//dmXP9giSbqJTdrow4DO19eBQyJHsNA4pEqOIuxT/eTAtfgYOOt6F+BLa
20khwXmHJbqm1JZyotQe1KO7QlHDaLGNSWvKhK8YqlDa3X8sHjJqFWEVPv2O+ISY
2laQOpobkw3Oj+5vgBAJKlyqnLyWwyiF312/Tg0HIwBxEDlhTzHvP34hwVqCOVe1
zKJ4sBPVVG+QzCRRFzH37WXYE8gT9ZiSyqgXbm5SIjFfngUhMRJsXAmJ9497jzsU
JVY+HakEIJHCCFdq6EtOZ1WmBY7d9jhjBFep9T3dx7QhDFCZKxN09KLOR12OdRyz
B6JIbycY3VdTUb9tSgAqnsjwUjIhjilk/VSaHnIPwoUEyPqP3x8BOShgz6PEoJhH
4bhEU1D6JFb9DdLrpZ5mkY+8YSJjcqq5GMj1x6VHyCZYRH8fmyFm0g7N8oaLQRvC
f9Sf4jU7SABFDOXlJgxp779uBIUgMcrf2GDZ9ITjxp6fLPBkCII8NCv7Gmi5Y9J+
0iFkHosjAx65bZnHa+mrH9dlgQHkh95dcy9oJnwVXct4yN/hBb9KOYchRGg0qTKW
RVHTwCwxYm1b7VaCqmzcM8/U6znAwirpBaIiq8S46/cBOQ0aRnbko15PnBZFbsWM
Y1a9bwGAjsf7ukSvnxc6ryf2cAJpcbKEJwem7F+2jem5PU2p7Qg=
=JnK0
-----END PGP SIGNATURE-----

Reply via email to