Critical Flaws in X Server and Xwayland: 12 Vulnerabilities Patched, Urgent Update Recommended
October 7, 2026
A sequence of newly disclosed CVEs targets the X.Org stack, with several heap and use-after-free vulnerabilities that could allow arbitrary code execution or denial of service.
CVE-2026-93520 stems from a heap out-of-bounds write in the XKB ChangeKeycodeRange path, raising potential for code execution or crashes.
CVE-2026-93515 involves a use-after-free in PRESENT EXTENSION cross-window notify handling, risking denial of service or information disclosure.
CVE-2026-93516 involves a use-after-free in XINPUT PASSIVE GRAB modifier device handling, with potential for denial of service or arbitrary code execution.
Two fixes address prior incomplete work: an unresolved issue from an earlier commit tied to CVE-2026-93520 and a repeat bug pattern in RRChangeOutputProperty for 93521, with the RandR output path corrected but the provider path remaining unpatched.
X.Org has issued new releases (xorg-server 21.1.25 and xwayland 24.1.14) in response to these vulnerabilities.
A security advisory notes that 12 vulnerabilities in the X server and Xwayland have been patched in these updated releases.
Several flaws depend on extensions enabled by default, notably CVE-2026-93515 (Present/SYNC) and CVE-2026-93519 (XFIXES, XTEST, and numerous active pointer barriers).
The broader bug set includes seven buffer overflows or out-of-bounds writes, three use-after-free bugs, one double free, and one out-of-bounds read.
Eleven of the twelve vulnerabilities affect both X server and Xwayland, with CVE-2026-93522 (a Glamor CopyArea heap overflow on GPU-accelerated systems) affecting only Xwayland.
Most vulnerabilities require an authenticated X client to trigger, though two CVEs do not specify this condition.
The disclosures come from TrendAI Zero Day Initiative and anonymous researchers, with multiple CVEs addressed in these releases.
Summary based on 2 sources
Get a daily email with more Tech stories
Sources

Help Net Security • Oct 7, 2026
Check your X.Org server version because a dozen vulnerabilities have been patched