======================================================================
X.Org Security Advisory: October 07, 2026

Issues in X.Org X server prior to xorg-server-21.1.25
and Xwayland prior to xwayland-24.1.14
======================================================================

Multiple issues have been found in the X server and Xwayland implementations
published by X.Org for which we are releasing security fixes for in
xorg-server-21.1.25 and xwayland-24.1.14.

* CVE-2026-88812: XKB SetGeometry TextDoodad Double Free

   _CheckSetDoodad() in xkb/xkb.c frees doodad->text.text on error but does
   not NULL the pointer. When the error path continues, _XkbClearDoodad() is
   called during cleanup and frees the same pointer again, resulting in a
   double free.

   An authenticated X client can trigger this by sending a crafted
   XkbSetGeometry request with a malformed TextDoodad entry that causes the
   initial error path to be taken.

   The double free can lead to heap corruption, potentially enabling arbitrary
   code execution or denial of service (crash).

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/0d1b1b0bad86
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-31221)

* CVE-2026-93515: Present Extension Cross-Window Notify Use-After-Free

   present_clear_window_notifies() does not unlink notify entries from the
   per-window list before freeing window_priv. When the window is
   subsequently destroyed or reused, the stale list entries are traversed,
   resulting in a use-after-free.

   An authenticated X client can trigger this by creating cross-window
   Present notifies and then destroying the target window. Both the
   Present and SYNC extensions must be enabled (they are by default).

   The use-after-free can lead to denial of service (crash) or potentially
   information disclosure.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/1b6955c3108e
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-31830)

* CVE-2026-93516: XInput Passive Grab modifierDevice Use-After-Free

   GrabRec stores a raw DeviceIntPtr for the modifierDevice without any
   lifetime management. When a master device is removed via
   XIRemoveMaster, the device is freed but the passive grab still holds a
   dangling pointer to it. Subsequent operations that dereference the
   modifierDevice pointer trigger a use-after-free.

   An authenticated X client with the ability to add and remove master
   devices (XI2) can trigger this by creating a passive grab, then
   removing the master device referenced as the modifier device. 

   The use-after-free can lead to denial of service (crash) or potentially
   arbitrary code execution.


   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/be5726341588
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-31832)

* CVE-2026-93517: GLX RenderLarge Heap Buffer Overflow

   In the GLX RenderLarge request handling, the buffer is allocated to the
   size of cmdlen but the subsequent memcpy copies dataBytes into it.
   There is no validation that dataBytes is less than or equal to cmdlen,
   allowing an attacker to write past the end of the allocated buffer.

   An authenticated X client can trigger this by sending a crafted GLX
   RenderLarge request where dataBytes exceeds cmdlen, causing a 
   heap buffer overflow.

   The heap buffer overflow can lead to arbitrary code execution or denial of
   service.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/2abe4632d793
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-31833)

* CVE-2026-93518: XKB ResizeKeyType Numeric Truncation

   In XkbResizeKeyType(), the size_syms variable is declared as unsigned
   short. The expression (nTotal * 15) / 10 can exceed 65535 for large
   nTotal values, and the result is truncated when assigned to the
   unsigned short variable. This causes an undersized allocation, and
   subsequent writes overflow the heap buffer.

   An authenticated X client can trigger this by sending XKB requests that
   cause a key type resize with a sufficiently large nTotal value.

   The heap buffer overflow resulting from the truncated allocation can lead
   to arbitrary code execution or denial of service.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/89101a6c6618
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-31834)

* CVE-2026-93519: XFixes Pointer Barrier Event List Buffer Overflow

   input_constrain_cursor() writes barrier events into a fixed-size buffer
   without checking bounds. When more than 100 pointer barriers are active,
   the writes overflow the fixed buffer on the stack or heap.

   An authenticated X client can trigger this by creating more than 100
   pointer barriers (using the XFIXES extension) and then generating pointer
   motion events (e.g. via XTEST). Both extensions are enabled by default.

   The buffer overflow can lead to arbitrary code execution or denial of
   service.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/1f42cc1f00d9
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-31938)

* CVE-2026-93520: XKB ChangeKeycodeRange Heap Out-of-Bounds Write

   This is caused by an incomplete fix in commit a3171732d.
   XkbAllocNames() still uses max_key_code+1 for the names->keys allocation
   size, while memset in the ChangeKeycodeRange path uses MAP_LENGTH which
   can be larger. This causes a heap out-of-bounds write when the keycode
   range is changed to a value where MAP_LENGTH exceeds max_key_code+1.

   An authenticated X client can trigger this by sending XKB requests that
   change the keycode range.

   The heap out-of-bounds write can lead to arbitrary code execution or denial
   of service.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b941a473e06f
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-31941)

* CVE-2026-93521: RandR ChangeProviderProperty Heap Buffer Overflow

   In RRChangeProviderProperty() with PrependMode, new_value.size is set to
   len instead of total_len. Additionally, the old_data offset calculation
   uses prop_value->size instead of len for the memcpy of existing data. This
   causes a heap buffer overflow when prepending property data, as the buffer
   is undersized and the copy offset is incorrect.

   This mirrors a bug pattern that was previously fixed in
   RRChangeOutputProperty but was not applied to the provider property path.

   An authenticated X client can trigger this by sending RandR
   ChangeProviderProperty requests with PrependMode on a system with RandR
   providers (standard on modern GPUs).

   The heap buffer overflow can lead to arbitrary code execution or denial of
   service.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/5dc9efd5a199
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-31944)

* CVE-2026-93522: Glamor CopyArea CPU-FBO Heap Buffer Overflow

   In glamor's CopyArea CPU-to-FBO path, the temporary buffer (tmp_bits)
   is sized based on the destination height but is indexed using source
   coordinates. When the source region is taller than the destination, writes
   overflow the allocated buffer.

   An authenticated X client can trigger this by performing a CopyArea
   operation between drawables with mismatched depth (depth-24 to depth-32
   or vice versa) where the source is taller than the destination, on a
   system using glamor/GPU acceleration.

   The heap buffer overflow can lead to arbitrary code execution or denial of
   service.

   This issue does not affect xorg-server-21.1.x

   Fixed in: xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/ad26c26bf795
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-32361)

* CVE-2026-93523: XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write

   The XI2 passive ungrab path (XIPassiveUngrabDevice) is missing the modifier
   validation that exists in the grab path and in legacy XI paths. Without
   checking against AllModifiersMask, a client can supply out-of-range modifier
   values that lead to an out-of-bounds write when the modifier is used as an
   index.

   An authenticated X client can trigger this by sending an
   XIPassiveUngrabDevice request with an out-of-range modifier value.

   The out-of-bounds write can lead to arbitrary code execution or denial of
   service.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/37a1847a60c6
   Found by: Anonymous working with TrendAI Zero Day Initiative.
             (ZDI-CAN-32366)

* CVE-2026-93524: XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read

   CheckKeySyms() in xkb/xkb.c populates a symsPerKey[] validation array with
   new key widths for keys in the SetMap request range, then continues filling
   entries for keys beyond the range. However, the second loop starts at index
   i = nKeySyms (the first loop's counter) rather than i = firstKeySym +
   nKeySyms. When firstKeySym is large and nKeySyms is small, the second loop
   overwrites symsPerKey[target] with the old width from the existing map.

   CheckKeyActions() then validates the wire action count against the stale old
   width and accepts it. In _XkbSetMap(), SetKeySyms() widens the key (resizing
   actions to nGroups * newWidth), but SetKeyActions() then resizes again to the
   old count. A subsequent XkbGetMap request reads XkbKeyNumActions() entries
   (derived from the new wider key_sym_map.width) from the shorter action
   allocation, causing an out-of-bounds heap read. The overread bytes are
   copied into the GetMap reply and sent back to the requesting client,
   producing a bounded heap information disclosure.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/cea71d0273e4
   Found by: WONJOON HWANG (@joon1337) working with TrendAI Zero Day
             Initiative.
             (ZDI-CAN-32408)

* CVE-2026-93536: GestureBuildSprite Use-After-Free

   GestureBuildSprite() copies raw WindowPtr values into the gesture sprite
   trace via CopySprite() without any reference counting or lifetime
   management. WindowGone() only repairs touch sprite traces when a window
   is destroyed -- gesture sprite traces are never checked or cleaned. This
   leaves stale WindowPtr references in gesture sprites.

   When DeliverOneGestureEvent() later dereferences the stale WindowPtr via
   DeepestSpriteWin(&gi->sprite)->drawable.id, it produces a use-after-free.
   The freed 4 bytes (drawable.id) can be read back, potentially leaking
   information about the contents of the freed memory region.

   Fixed in: xorg-server-21.1.25 and xwayland-24.1.14
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/efcfd8acc754
   Found by: 4nibhal working with TrendAI Zero Day Initiative.
             (ZDI-CAN-32753)

Reply via email to