This release contains the fixes for the issues reported in today's security advisory: https://lists.x.org/archives/xorg-announce/2026-July/003716.html
- CVE-2026-55999: glamor Font Atlas Heap Buffer Overflow
- CVE-2026-56000: GLX contextTags Use-After-Free in CommonMakeCurrent()
In addition we have a few other smaller cleanup fixes.
Mikhail Dmitrichenko (1):
xkb: preserve buffer on realloc failure
Olivier Fourdan (4):
dix: Silence a compiler warning in doListFontsAndAliases()
dix: Silent static analyzer warning
dix: Silence a compiler warning in doListFontsWithInfo()
Xi: Check window attribute is valid in XIChangeCursor
Peter Hutterer (7):
dix/colormap: fix out-of-bounds read in FindColorInRootCmap
glx: fix duplicate tagInfo->vendor = NULL assignment
glamor: fix an error path cleanup
glx: free old context tag before allocating new one in CommonMakeCurrent
fb/mi/glamor: reject glyphs with negative dimensions
glamor: reject fonts with per-glyph metrics exceeding maxbounds
Bump version to 24.1.13
git tag: xwayland-24.1.13
https://xorg.freedesktop.org/archive/individual/xserver/xwayland-24.1.13.tar.xz
SHA256: 173aea3d6f79609164c04528e1c8e4c9b60fcd59391c3c9dad4667297d727fb6
xwayland-24.1.13.tar.xz
SHA512:
e06e58025b441892fdd17ac55fd5c7e137bffc941b76ad784dc008047c778c6ee2895fcc47b9e8c74b1d8372491e69c39933c4186aec4df55571614f8ba98e3c
xwayland-24.1.13.tar.xz
PGP:
https://xorg.freedesktop.org/archive/individual/xserver/xwayland-24.1.13.tar.xz.sig
signature.asc
Description: PGP signature
