X.Org has released patches for a dozen security vulnerabilities affecting its X server and Xwayland components, with updates available in versions xorg-server 21.1.25 and xwayland-24.1.14. Nine of these flaws are critical, potentially allowing for arbitrary code execution, while the remaining three could lead to server crashes or information disclosure.
The majority of the vulnerabilities, specifically ten out of twelve, can be triggered by an authenticated X client, meaning a program that has already established a connection with the server. The conditions for CVE-2026-93524 and CVE-2026-93536 do not specify this requirement.
Eleven of the twelve identified issues impact both the X server and Xwayland. However, CVE-2026-93522, described as a heap buffer overflow within Glamor's CopyArea code on GPU-accelerated systems, is exclusive to Xwayland.
The nature of the flaws varies, including seven buffer overflows or out-of-bounds writes, three use-after-free vulnerabilities, one double free error, and one out-of-bounds read. Two specific vulnerabilities are tied to extensions that are enabled by default: CVE-2026-93515 requires the Present and SYNC extensions, while CVE-2026-93519 necessitates XFIXES and XTEST, in addition to over 100 active pointer barriers.
Two of the recently released fixes address issues stemming from prior incomplete patches. CVE-2026-93520 resolves a flaw that originated from an incomplete fix in commit a3171732d. Similarly, CVE-2026-93521 addresses a recurring bug pattern previously fixed in RRChangeOutputProperty, where the initial correction was applied to the RandR output path but not to the provider path.
Users operating the X server or Xwayland are advised to check their installed versions against the patched releases, 21.1.25 and 24.1.14, respectively. Each CVE entry includes a link to its corresponding fix commit on freedesktop.org GitLab for further details.
The vulnerabilities are identified by CVEs ranging from CVE-2026-93515 to CVE-2026-93526, and CVE-2026-93536. The X.Org Foundation confirmed the patching of these twelve vulnerabilities, which were discovered and reported by security researchers.






