Security 11033 Published by

X.Org released twelve security fixes today across three simultaneous packages: xorg-server 21.1.25, the standalone 26.1.0 release candidate 26.0.99.903, and xwayland 24.1.14. The vulnerabilities, which includes double frees, use-after-frees, heap overflows, numeric truncation, and out-of-bounds reads and spana the XKB, GLX, RandR, XFixes, XInput2, Present, and glamor extensions. Most can be triggered by an authenticated local X client, meaning a compromised app on your machine could seize the session or leak memory. Users on Debian, Ubuntu, Arch, XQuartz, or Windows X servers should update as soon as the packages propagate, with multi-user hosts treated as highest priority.





X.Org ships twelve security fixes for the X server and Xwayland

A single burst of releases today hardened the X display server against memory bugs that any local application can trigger, delivered in three separate packages at once.

The X.Org Foundation pushed out xorg-server 21.1.25, a third release candidate for the standalone 26.1.0 ( serving as 26.0.99.903), and xwayland 24.1.14 within about thirty minutes of one another. Project leads Peter Hutterer and Alan Coopersmith posted to the xorg-announce mailing list, with the security advisory landing first at 01:08 UTC. Every one of the twelve vulnerabilities traces to researchers working through TrendAI's Zero Day Initiative, the vulnerability bounty program backed by Trend Micro.

Xorg

The interesting part is the spread. These aren't some obscure corner of the code either. The flaws include double frees, use-after-frees, heap buffer overflows, numeric truncation, and out-of-bounds reads, landing across exactly the extensions applications hit every day: XKB, GLX, RandR, XFixes, XInput2, Present, and the glamor acceleration layer.

Keep in mind that almost all of them need an authenticated local X client to fire. That's the long-standing X threat model straight up: a compromised or malicious app on your own machine going after the display server and everything it guards. The server runs privileged, owning your keyboard, your mouse, your GPU, and every window on screen. Get in and you can take over the session, log keystrokes, or just crash the whole thing.

What's actually patched

A couple of entries stand out. CVE-2026-93524, an XKB SetMap info-disclosure bug, reads a little past a heap allocation and hands those stray bytes back to the requesting client. That's genuine information leakage rather than a plain crash, and it was one of two findings that went public: Wonjoon Hwang got the credit.

The other standout is an odd one out. CVE-2026-93522 is a glamor CopyArea heap overflow that simply doesn't touch the stable 21.1.x line. It only fires when a depth-24 to depth-32 mismatch meets GPU-accelerated glamor, which is why only xwayland 24.1.14 carries the fix and 21.1.25 does not.

The rest follow familiar failure modes. A double free in the XKB doodad handler (CVE-2026-88812) leaves a dangling pointer behind. A use-after-free in the Present extension (CVE-2026-93515) walks stale window notifications. Numeric truncation in XKB's ResizeKeyType (CVE-2026-93518) allocates a buffer too small, then overflows it. Most findings came in anonymously, but the second public credit went to researcher 4nibhal for a gesture-sprite use-after-free (CVE-2026-93536).

That anonymous-or-credited split is the whole point of ZDI. Independent researchers surface bugs before vendors have patches, and this batch shows the coordination coming back in under a single day.

The three release lines, explained

The version numbers are genuinely confusing, so here's how they break down.

xorg-server 21.1.25 is the active security-maintenance branch of the classic monolithic server. It takes backported fixes and no new features, which is why it's the one that lands in Debian's xserver-xorg-core and most distro package managers.

The 26.0.99.903 release is a different beast. That 99 in the version string marks it as a pre-release, specifically the third candidate heading toward standalone 26.1.0, so it carries the same twelve fixes plus real development work: SIGBUS handling for truncated GPU shared-memory fences, shader-link cleanup, and a new step that wires ruff formatting into CI. Coopersmith's invite was explicit: test the candidate, file issues at the project's GitLab if you hit regressions, and do it all before 26.1.0 finalizes.

xwayland 24.1.14 keeps its own numbering and shares the security fixes, adding a cluster of mode-handling hardening from Olivier Fourdan that makes the compatibility layer far more resilient on odd or misconfigured monitor setups.

The versioning is a headache, but the payoff is simple. The stable line you're likely on gets the same protection as the dev line.

There's a little more context worth having. The desktop world has drifted toward Wayland for years, yet Xwayland has only grown more important, since every legacy X11 app that never migrated still routes through it. And there's been visible friction over the project's pace. A fork named X11Libre shipped in June 2025, reportedly to protest perceived stagnation and to reject systemd in favor of seatd. A batch like this brings dozens of contributors, a fast disclosure cycle, and a concrete security win, which reads like a counterargument to fragmentation, even as the standalone 26.x line itself churns with activity.

The X server is forty years old now, and its core threat model hasn't changed much since: a high-privilege process parsing untrusted input, where any C memory error becomes a security outcome. Null guards, bounds checks, and lifetime management are exactly the kind of incremental hardening this codebase has needed for a long while.

The fix itself is not complicated. Update.

On Debian and Ubuntu-family distros, wait for xserver-xorg-core and xwayland to flow through the security repos, then install. Arch and Arch-based builds usually track upstream fast, so a pacman -Syu tends to do it. macOS users on XQuartz and Windows users on VcXsrv, Xming, or Cygwin/X should watch those projects' own update channels instead of waiting on a distro.

If you run multi-user hardware, whether a shared workstation, a build box, or a virtual machine, raise the priority, since any local client is potentially an attacker. And if you happen to be testing the standalone line, note that 26.0.99.903 is still a release candidate, so report issues if you hit regressions.

Head here to the X.Org security advisory.