Critical Flaws in X Server and Xwayland: 12 Vulnerabilities Patched, Urgent Update Recommended

October 7, 2026
Critical Flaws in X Server and Xwayland: 12 Vulnerabilities Patched, Urgent Update Recommended
  • A sequence of newly disclosed CVEs targets the X.Org stack, with several heap and use-after-free vulnerabilities that could allow arbitrary code execution or denial of service.

  • CVE-2026-93520 stems from a heap out-of-bounds write in the XKB ChangeKeycodeRange path, raising potential for code execution or crashes.

  • CVE-2026-93515 involves a use-after-free in PRESENT EXTENSION cross-window notify handling, risking denial of service or information disclosure.

  • CVE-2026-93516 involves a use-after-free in XINPUT PASSIVE GRAB modifier device handling, with potential for denial of service or arbitrary code execution.

  • Two fixes address prior incomplete work: an unresolved issue from an earlier commit tied to CVE-2026-93520 and a repeat bug pattern in RRChangeOutputProperty for 93521, with the RandR output path corrected but the provider path remaining unpatched.

  • X.Org has issued new releases (xorg-server 21.1.25 and xwayland 24.1.14) in response to these vulnerabilities.

  • A security advisory notes that 12 vulnerabilities in the X server and Xwayland have been patched in these updated releases.

  • Several flaws depend on extensions enabled by default, notably CVE-2026-93515 (Present/SYNC) and CVE-2026-93519 (XFIXES, XTEST, and numerous active pointer barriers).

  • The broader bug set includes seven buffer overflows or out-of-bounds writes, three use-after-free bugs, one double free, and one out-of-bounds read.

  • Eleven of the twelve vulnerabilities affect both X server and Xwayland, with CVE-2026-93522 (a Glamor CopyArea heap overflow on GPU-accelerated systems) affecting only Xwayland.

  • Most vulnerabilities require an authenticated X client to trigger, though two CVEs do not specify this condition.

  • The disclosures come from TrendAI Zero Day Initiative and anonymous researchers, with multiple CVEs addressed in these releases.

Summary based on 2 sources


Get a daily email with more Tech stories

More Stories