Debian 11039 Published by

Debian has released latest security patches to address flaws across xorg-server, Chromium, PostgreSQL 17, apr-util, xdg-dbus-proxy, and python-django. The advisories target race conditions, stack buffer overflows, use-after-free errors, and malformed request handling that could allow privilege escalation, arbitrary code execution, or data exposure. Each affected package now includes fixed versions for Debian 11, Debian 12, and the Debian 13 stable distribution.

[DLA 4738-1] xorg-server security update
[DLA 4737-1] xorg-server security update
[DSA 6433-1] xdg-dbus-proxy security update
ELA-1808-1 python-django security update (by )
[DSA 6437-1] apr-util security update
[DSA 6436-1] chromium security update
[DLA 4739-1] chromium security update
[DSA 6438-1] postgresql-17 security update




[SECURITY] [DLA 4738-1] xorg-server security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4738-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Arnaud Rebillout
August 13, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : xorg-server
Version : 2:1.20.11-1+deb11u18
CVE ID : CVE-2022-49737 CVE-2026-33999 CVE-2026-34000 CVE-2026-34001
CVE-2026-34002 CVE-2026-34003 CVE-2026-50256 CVE-2026-50257
CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261
CVE-2026-50262 CVE-2026-50263 CVE-2026-50264
Debian Bug : 1081338 1138680

Several vulnerabilities were discovered in the Xorg X server, which may
result in privilege escalation if the X server is running privileged.

CVE-2022-49737

In X.Org X server 20.11 through 21.1.16, when a client application
uses easystroke for mouse gestures, the main thread modifies various
data structures used by the input thread without acquiring a lock,
aka a race condition. In particular, AttachDevice in dix/devices.c
does not acquire an input lock.

CVE-2026-33999

A flaw was found in the X.Org X server. This integer underflow
vulnerability, specifically in the XKB compatibility map handling,
allows an attacker with local or remote X11 server access to trigger
a buffer read overrun. This can lead to memory-safety violations and
potentially a denial of service (DoS) or other severe impacts.

CVE-2026-34000

A flaw was found in the X.Org X server. This out-of-bounds read
vulnerability in the XKB geometry processing, specifically within the
`CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an
attacker to read uninitialized or out-of-bounds memory. An attacker
with a connection to the X11 server, either locally or remotely, can
exploit this without user interaction. This could lead to the
disclosure of memory contents or cause a denial of service by
crashing the server. Source

CVE-2026-34001

A flaw was found in the X.Org X server. This use-after-free
vulnerability occurs in the XSYNC fence triggering logic,
specifically within the miSyncTriggerFence() function. An attacker
with access to the X11 server can exploit this without user
interaction, leading to a server crash and potentially enabling
memory corruption. This could result in a denial of service or
further compromise of the system.

CVE-2026-34002

A flaw was found in the X.Org X server. This vulnerability, an
out-of-bounds read, affects the XKB (X Keyboard Extension) modifier
map handling. An attacker with access to the X11 server can exploit
this by sending a malformed request, which causes the server to read
beyond its intended memory boundaries. This can lead to the exposure
of sensitive information or cause the server to crash, resulting in a
denial of service.

CVE-2026-34003

A flaw was found in the X.Org X server's XKB key types request
validation. A local attacker could send a specially crafted request
to the X server, leading to an out-of-bounds memory access
vulnerability. This could result in the disclosure of sensitive
information or cause the server to crash, leading to a Denial of
Service (DoS). In certain configurations, higher impact outcomes may
be possible.

CVE-2026-50256

A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. A mismatch between the X server and the libXfont2
library's maximum font name length can cause a stack buffer overflow
during font alias resolution. The server allocates a 256 byte stack
buffer but libXfont2's alias target name length is 1024 bytes. A font
alias name between 257 and 1023 bytes causes the X server to copy
that name into the undersized stack buffer without further checks.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.

CVE-2026-50257

A use-after-free flaw was found in the X.Org X server and Xwayland in
miSyncDestroyFence(). A client that sets up multiple fence triggers
can trigger a use-after-free function pointer call. An attacker would
connect to the X server to set up a fence and await that fence, then
a second X connection destroys the fence, causing the use-after-free.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.

CVE-2026-50258

A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. The X server has multiple stack buffers sized
XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not
verify or clamp non-canonical key types to XkbMaxShiftLevel. A client
can change key types to excessive shift levels and trigger stack
overflows. This is caused by an incomplete fix of CVE-2025-26597.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.

CVE-2026-50259

A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer
mapWidths[256] indexed by key type index. The helper function
CheckKeyTypes() writes to this buffer at a client-controlled offset,
allowing a stack buffer overflow. This may be used to crash the
server, or for privilege escalation if the X server runs as root.

CVE-2026-50260

A use-after-free flaw was found in the X.Org X server and Xwayland in
FreeCounter(). A client that sets up multiple SyncCounters and awaits
on those triggers can trigger a use-after-free when destroying those
counters via a second client connection. This may be used to crash
the server, or for privilege escalation if the X server runs as root.

CVE-2026-50261

A use-after-free flaw was found in the X.Org X server and Xwayland in
SyncChangeCounter(). A client that sets up multiple SyncCounters can
trigger a use-after-free when destroying those counters via a second
client connection while changing those counters. This may be used to
crash the server, or for privilege escalation if the X server runs as
root.

CVE-2026-50262

An out-of-bounds read flaw was found in the X.Org X server and
Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size
validation check can read a client-controlled number of bytes,
exceeding the request buffer, leading to information disclosure. A
write path also exists but requires byte-swapped clients which is
disabled by default.

CVE-2026-50263

A use-after-free flaw was found in the X.Org X server and Xwayland in
CreateSaverWindow(). A client can trigger a use-after-free read after
changing window attributes and forcing the screen saver, leading to
information disclosure.

CVE-2026-50264

An out-of-bounds write flaw was found in the X.Org X server and
Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that
requests multiple DRI2BufferBackLeft attachments and one
DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may
be used to crash the server, or for privilege escalation if the X
server runs as root.

For Debian 12 bullseye, these problems have been fixed in version
2:1.20.11-1+deb11u18.

We recommend that you upgrade your xorg-server packages.

For the detailed security status of xorg-server please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/xorg-server

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DLA 4737-1] xorg-server security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4737-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Arnaud Rebillout
August 13, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : xorg-server
Version : 2:21.1.7-3+deb12u13
CVE ID : CVE-2022-49737 CVE-2026-50256 CVE-2026-50257 CVE-2026-50258
CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262
CVE-2026-50263 CVE-2026-50264
Debian Bug : 1081338 1138680

Several vulnerabilities were discovered in the Xorg X server, which may
result in privilege escalation if the X server is running privileged.

CVE-2022-49737

In X.Org X server 20.11 through 21.1.16, when a client application
uses easystroke for mouse gestures, the main thread modifies various
data structures used by the input thread without acquiring a lock,
aka a race condition. In particular, AttachDevice in dix/devices.c
does not acquire an input lock.

CVE-2026-50256

A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. A mismatch between the X server and the libXfont2
library's maximum font name length can cause a stack buffer overflow
during font alias resolution. The server allocates a 256 byte stack
buffer but libXfont2's alias target name length is 1024 bytes. A font
alias name between 257 and 1023 bytes causes the X server to copy
that name into the undersized stack buffer without further checks.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.

CVE-2026-50257

A use-after-free flaw was found in the X.Org X server and Xwayland in
miSyncDestroyFence(). A client that sets up multiple fence triggers
can trigger a use-after-free function pointer call. An attacker would
connect to the X server to set up a fence and await that fence, then
a second X connection destroys the fence, causing the use-after-free.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.

CVE-2026-50258

A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. The X server has multiple stack buffers sized
XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not
verify or clamp non-canonical key types to XkbMaxShiftLevel. A client
can change key types to excessive shift levels and trigger stack
overflows. This is caused by an incomplete fix of CVE-2025-26597.
This may be used to crash the server, or for privilege escalation if
the X server runs as root.

CVE-2026-50259

A stack-based buffer overflow flaw was found in the X.Org X server
and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer
mapWidths[256] indexed by key type index. The helper function
CheckKeyTypes() writes to this buffer at a client-controlled offset,
allowing a stack buffer overflow. This may be used to crash the
server, or for privilege escalation if the X server runs as root.

CVE-2026-50260

A use-after-free flaw was found in the X.Org X server and Xwayland in
FreeCounter(). A client that sets up multiple SyncCounters and awaits
on those triggers can trigger a use-after-free when destroying those
counters via a second client connection. This may be used to crash
the server, or for privilege escalation if the X server runs as root.

CVE-2026-50261

A use-after-free flaw was found in the X.Org X server and Xwayland in
SyncChangeCounter(). A client that sets up multiple SyncCounters can
trigger a use-after-free when destroying those counters via a second
client connection while changing those counters. This may be used to
crash the server, or for privilege escalation if the X server runs as
root.

CVE-2026-50262

An out-of-bounds read flaw was found in the X.Org X server and
Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size
validation check can read a client-controlled number of bytes,
exceeding the request buffer, leading to information disclosure. A
write path also exists but requires byte-swapped clients which is
disabled by default.

CVE-2026-50263

A use-after-free flaw was found in the X.Org X server and Xwayland in
CreateSaverWindow(). A client can trigger a use-after-free read after
changing window attributes and forcing the screen saver, leading to
information disclosure.

CVE-2026-50264

An out-of-bounds write flaw was found in the X.Org X server and
Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that
requests multiple DRI2BufferBackLeft attachments and one
DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may
be used to crash the server, or for privilege escalation if the X
server runs as root.

For Debian 12 bookworm, these problems have been fixed in version
2:21.1.7-3+deb12u13.

We recommend that you upgrade your xorg-server packages.

For the detailed security status of xorg-server please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/xorg-server

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DSA 6433-1] xdg-dbus-proxy security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6433-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 12, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : xdg-dbus-proxy
CVE ID : not yet available

It was discovered that incorrect validation of broadcast policy rules in
xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed a
malicious Flatpak application to monitor signals on the D-Bus session
bus.

For the stable distribution (trixie), this problem has been fixed in
version 0.1.6-1+deb13u2.

We recommend that you upgrade your xdg-dbus-proxy packages.

For the detailed security status of xdg-dbus-proxy please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/xdg-dbus-proxy

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


ELA-1808-1 python-django security update (by )


Package : python-django


Version : 1:1.10.7-2+deb9u31 (stretch), 1:1.11.29-1+deb10u20 (buster)


Related CVEs :

CVE-2026-15337

CVE-2026-15920



Two issues were discovered in Django, the Python-based web
development framework:


CVE-2026-15337: Avoid a potential denial-of-service vulnerability in the
check_for_language() method in the django.utils.translation module. This
method was subject to a potential denial-of-service (DoS) attack when
checking many distinct, very long language codes. To mitigate this
vulnerability, language codes longer than 500 characters are now rejected
before the cached lookup.


CVE-2026-15920: Prevent a potential cross-site scripting (XSS) attack via
bogus URLField values in the Django admin. The admin renders URLField
values as clickable links on ‘changelist’ views and read-only fields. This
link was hitherto generated without validating the value as a safe URL, so a
stored value using a potentially dangerous scheme was rendered as a link.
URLField values shown via display_for_field are now validated using the
URLValidator class before a link is rendered and displayed as plain text
if validation fails.


ELA-1808-1 python-django security update (by )



[SECURITY] [DSA 6437-1] apr-util security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6437-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 13, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : apr-util
CVE ID : CVE-2025-49506 CVE-2026-32327 CVE-2026-34501 CVE-2026-34502
Debian Bug : 1143837

Several vulnerabilities were discovered in apr-util, the Apache Portable
Runtime Utility library, which could result in denial of service or
potentially the execution of arbitrary code.

For the stable distribution (trixie), these problems have been fixed in
version 1.6.3-3+deb13u1.

We recommend that you upgrade your apr-util packages.

For the detailed security status of apr-util please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/apr-util

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6436-1] chromium security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6436-1 security@debian.org
https://www.debian.org/security/ Andres Salomon
August 13, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium
CVE ID : CVE-2026-19556 CVE-2026-19557 CVE-2026-19558 CVE-2026-19559
CVE-2026-19560

Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.

For the stable distribution (trixie), these problems have been fixed in
version 151.0.7922.137-1~deb13u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4739-1] chromium security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4739-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
August 13, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : chromium
Version : 151.0.7922.137-1~deb12u1
CVE ID : CVE-2026-19556 CVE-2026-19557 CVE-2026-19558 CVE-2026-19559
CVE-2026-19560

Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.

For Debian 12 bookworm, these problems have been fixed in version
151.0.7922.137-1~deb12u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DSA 6438-1] postgresql-17 security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6438-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 13, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : postgresql-17
CVE ID : CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471
CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664
CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670
CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677
CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681
CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241
CVE-2026-18024 CVE-2026-18408 CVE-2026-19385

Multiple security issues were discovered in PostgreSQL, which may
result in execution of arbitrary code, incorrect authentication,
information disclosure, or privilege escalation.

The upstream fix to address CVE-2026-6471 requires additional changes
to the configuration if some extensions are used. This affects the
postgresql-17-wal2json, postgresql-17-squeeze, postgresql-17-pg-rewrite
and postgresql-17-decoderbufs extensions included in Debian.
Quoting from the changelog:

| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
|
| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
| for logical decoding, allowing exploits of various sorts. To
| allow locking this down without breaking setups that worked
| before, introduce a whitelist of allowed output plugins.
|
| By default, only the output plugins shipped as part of
| PostgreSQL (`pgoutput` and `test_decoding`) are included in
|`output_plugin_libraries`. Installations that rely on other
| output plugins must add them after updating the server, for
| example
|
| output_plugin_libraries = 'pgoutput, test_decoding, my_trusted_decoder'

For the stable distribution (trixie), these problems have been fixed in
version 17.11-0+deb13u1.

We recommend that you upgrade your postgresql-17 packages.

For the detailed security status of postgresql-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-17

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/