-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4738-1 [email protected]
https://www.debian.org/lts/security/ Arnaud Rebillout
August 13, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : xorg-server
Version : 2:1.20.11-1+deb11u18
CVE ID : CVE-2022-49737 CVE-2026-33999 CVE-2026-34000 CVE-2026-34001
CVE-2026-34002 CVE-2026-34003 CVE-2026-50256 CVE-2026-50257
CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261
CVE-2026-50262 CVE-2026-50263 CVE-2026-50264
Debian Bug : 1081338 1138680
Several vulnerabilities were discovered in the Xorg X server, which may
result in privilege escalation if the X server is running privileged.
CVE-2022-49737
In X.Org X server 20.11 through 21.1.16, when a client application
uses easystroke for mouse gestures, the main thread modifies various
data structures used by the input thread without acquiring a lock,
aka a race condition. In particular, AttachDevice in dix/devices.c
does not acquire an input lock.
CVE-2026-33999
A flaw was found in the X.Org X server. This integer underflow
vulnerability, specifically in the XKB compatibility map handling,
allows an attacker with local or remote X11 server access to trigger
a buffer read overrun. This can lead to memory-safety violations and
potentially a denial of service (DoS) or other severe impacts.
CVE-2026-34000
A flaw was found in the X.Org X server. This out-of-bounds read
vulnerability in the XKB geometry processing, specifically within the
`CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an
attacker to read uninitialized or out-of-bounds memory. An attacker
with a connection to the X11 server, either locally or remotely, can
exploit this without user interaction. This could lead to the
disclosure of memory contents or cause a denial of service by
crashing the server. Source
CVE-2026-34001
A flaw was found in the X.Org X server. This use-after-free
vulnerability occurs in the XSYNC fence triggering logic,
specifically within the miSyncTriggerFence() function. An attacker
with access to the X11 server can exploit this without user
interaction, leading to a server crash and potentially enabling
memory corruption. This could result in a denial of service or
further compromise of the system.
CVE-2026-34002
A flaw was found in the X.Org X server. This vulnerability, an
out-of-bounds read, affects the XKB (X Keyboard Extension) modifier
map handling. An attacker with access to the X11 server can exploit
this by sending a malformed request, which causes the server to read
beyond its intended memory boundaries. This can lead to the exposure
of sensitive information or cause the server to crash, resulting in a
denial of service.
CVE-2026-34003
A flaw was found in the X.Org X server's XKB key types request
validation. A local attacker could send a specially crafted request
to the X server, leading to an out-of-bounds memory access
vulnerability. This could result in the disclosure of sensitive
information or cause the server to crash, leading to a Denial of
Service (DoS). In certain configurations, higher impact outcomes may
be possible.
CVE-2026-50256
A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. A mismatch between the X server and the libXfont2
library's maximum font name length can cause a stack buffer overflow
during font alias resolution. The server allocates a 256 byte stack
buffer but libXfont2's alias target name length is 1024 bytes. A font
alias name between 257 and 1023 bytes causes the X server to copy
that name into the undersized stack buffer without further checks.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.
CVE-2026-50257
A use-after-free flaw was found in the X.Org X server and Xwayland in
miSyncDestroyFence(). A client that sets up multiple fence triggers
can trigger a use-after-free function pointer call. An attacker would
connect to the X server to set up a fence and await that fence, then
a second X connection destroys the fence, causing the use-after-free.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.
CVE-2026-50258
A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. The X server has multiple stack buffers sized
XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not
verify or clamp non-canonical key types to XkbMaxShiftLevel. A client
can change key types to excessive shift levels and trigger stack
overflows. This is caused by an incomplete fix of CVE-2025-26597.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.
CVE-2026-50259
A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer
mapWidths[256] indexed by key type index. The helper function
CheckKeyTypes() writes to this buffer at a client-controlled offset,
allowing a stack buffer overflow. This may be used to crash the
server, or for privilege escalation if the X server runs as root.
CVE-2026-50260
A use-after-free flaw was found in the X.Org X server and Xwayland in
FreeCounter(). A client that sets up multiple SyncCounters and awaits
on those triggers can trigger a use-after-free when destroying those
counters via a second client connection. This may be used to crash
the server, or for privilege escalation if the X server runs as root.
CVE-2026-50261
A use-after-free flaw was found in the X.Org X server and Xwayland in
SyncChangeCounter(). A client that sets up multiple SyncCounters can
trigger a use-after-free when destroying those counters via a second
client connection while changing those counters. This may be used to
crash the server, or for privilege escalation if the X server runs as
root.
CVE-2026-50262
An out-of-bounds read flaw was found in the X.Org X server and
Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size
validation check can read a client-controlled number of bytes,
exceeding the request buffer, leading to information disclosure. A
write path also exists but requires byte-swapped clients which is
disabled by default.
CVE-2026-50263
A use-after-free flaw was found in the X.Org X server and Xwayland in
CreateSaverWindow(). A client can trigger a use-after-free read after
changing window attributes and forcing the screen saver, leading to
information disclosure.
CVE-2026-50264
An out-of-bounds write flaw was found in the X.Org X server and
Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that
requests multiple DRI2BufferBackLeft attachments and one
DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may
be used to crash the server, or for privilege escalation if the X
server runs as root.
For Debian 12 bullseye, these problems have been fixed in version
2:1.20.11-1+deb11u18.
We recommend that you upgrade your xorg-server packages.
For the detailed security status of xorg-server please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/xorg-server
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE0Kl7ndbut+9n4bYs5yXoeRRgAhYFAmp9T7EACgkQ5yXoeRRg
AhYP9Q//dmXP9giSbqJTdrow4DO19eBQyJHsNA4pEqOIuxT/eTAtfgYOOt6F+BLa
20khwXmHJbqm1JZyotQe1KO7QlHDaLGNSWvKhK8YqlDa3X8sHjJqFWEVPv2O+ISY
2laQOpobkw3Oj+5vgBAJKlyqnLyWwyiF312/Tg0HIwBxEDlhTzHvP34hwVqCOVe1
zKJ4sBPVVG+QzCRRFzH37WXYE8gT9ZiSyqgXbm5SIjFfngUhMRJsXAmJ9497jzsU
JVY+HakEIJHCCFdq6EtOZ1WmBY7d9jhjBFep9T3dx7QhDFCZKxN09KLOR12OdRyz
B6JIbycY3VdTUb9tSgAqnsjwUjIhjilk/VSaHnIPwoUEyPqP3x8BOShgz6PEoJhH
4bhEU1D6JFb9DdLrpZ5mkY+8YSJjcqq5GMj1x6VHyCZYRH8fmyFm0g7N8oaLQRvC
f9Sf4jU7SABFDOXlJgxp779uBIUgMcrf2GDZ9ITjxp6fLPBkCII8NCv7Gmi5Y9J+
0iFkHosjAx65bZnHa+mrH9dlgQHkh95dcy9oJnwVXct4yN/hBb9KOYchRGg0qTKW
RVHTwCwxYm1b7VaCqmzcM8/U6znAwirpBaIiq8S46/cBOQ0aRnbko15PnBZFbsWM
Y1a9bwGAjsf7ukSvnxc6ryf2cAJpcbKEJwem7F+2jem5PU2p7Qg=
=JnK0
-----END PGP SIGNATURE-----