Check your X.Org server version because a dozen vulnerabilities have been patched
X.Org fixed 12 security flaws in the X server and Xwayland, with the repairs shipping in xorg-server 21.1.25 and xwayland-24.1.14. Nine of the flaws can lead to arbitrary code execution. The other three can crash the server or disclose information.

Ten of the 12 entries say an authenticated X client can trigger the flaw, meaning a program the server already accepts a connection from. The entries for CVE-2026-93524 and CVE-2026-93536 do not state that condition. Eleven of the 12 affect both the X server and Xwayland. CVE-2026-93522, a heap buffer overflow in Glamor’s CopyArea code on GPU-accelerated systems, affects only Xwayland.
What the bugs are
Seven are buffer overflows or out-of-bounds writes, three are use-after-free bugs (the server keeps using memory it already released), one is a double free, and one is an out-of-bounds read. Two flaws depend on extensions the advisory says are on by default: CVE-2026-93515 needs Present and SYNC, and CVE-2026-93519 needs XFIXES and XTEST plus more than 100 active pointer barriers.
Two of the fixes finish earlier work. CVE-2026-93520 comes from an incomplete fix in commit a3171732d. CVE-2026-93521 repeats a bug pattern already fixed in RRChangeOutputProperty. The RandR output path got the fix; the provider path did not.
What to check
If you run the X server or Xwayland, compare your installed version with 21.1.25 and 24.1.14. Each CVE entry links its fix commit on freedesktop.org GitLab.