Check your X.Org server version because a dozen vulnerabilities have been patched

X.Org fixed 12 security flaws in the X server and Xwayland, with the repairs shipping in xorg-server 21.1.25 and xwayland-24.1.14. Nine of the flaws can lead to arbitrary code execution. The other three can crash the server or disclose information.

X.Org server vulnerabilities

Ten of the 12 entries say an authenticated X client can trigger the flaw, meaning a program the server already accepts a connection from. The entries for CVE-2026-93524 and CVE-2026-93536 do not state that condition. Eleven of the 12 affect both the X server and Xwayland. CVE-2026-93522, a heap buffer overflow in Glamor’s CopyArea code on GPU-accelerated systems, affects only Xwayland.

What the bugs are

Seven are buffer overflows or out-of-bounds writes, three are use-after-free bugs (the server keeps using memory it already released), one is a double free, and one is an out-of-bounds read. Two flaws depend on extensions the advisory says are on by default: CVE-2026-93515 needs Present and SYNC, and CVE-2026-93519 needs XFIXES and XTEST plus more than 100 active pointer barriers.

Two of the fixes finish earlier work. CVE-2026-93520 comes from an incomplete fix in commit a3171732d. CVE-2026-93521 repeats a bug pattern already fixed in RRChangeOutputProperty. The RandR output path got the fix; the provider path did not.

What to check

If you run the X server or Xwayland, compare your installed version with 21.1.25 and 24.1.14. Each CVE entry links its fix commit on freedesktop.org GitLab.

Don't miss