SUSE alert SUSE-SU-2026:2426-1 (xwayland)
| From: | SLE-SECURITY-UPDATES <null@suse.de> | |
| To: | sle-security-updates@lists.suse.com | |
| Subject: | SUSE-SU-2026:2426-1: important: Security update for xwayland | |
| Date: | Wed, 17 Jun 2026 16:31:05 -0000 | |
| Message-ID: | <178171386516.19795.13038427406976276141@d93ac1748d57> |
# Security update for xwayland Announcement ID: SUSE-SU-2026:2426-1 Release Date: 2026-06-17T09:50:05Z Rating: important References: * bsc#1266294 * bsc#1266295 * bsc#1266296 * bsc#1266297 * bsc#1266298 * bsc#1266299 * bsc#1266300 * bsc#1266301 Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that has eight security fixes can now be installed. ## Description: This update for xwayland fixes the following issues: * CreateSaverWindow Use-After-Free Information Disclosure. (bsc#1266301) * Font Alias Stack-based Buffer Overflow. (bsc#1266294) * GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write. (bsc#1266300) * XKB Key Types Stack-based Buffer Overflow. (bsc#1266296) * XKB SetMap Request Stack-based Buffer Overflow. (bsc#1266297) * XSYNC Use-After-Free in FreeCounter(). (bsc#1266298) * XSYNC Use-After-Free in miSyncDestroyFence(). (bsc#1266295) * XSYNC Use-After-Free in SyncChangeCounter(). (bsc#1266299) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2426=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * xwayland-24.1.5-150700.3.19.1 * xwayland-debuginfo-24.1.5-150700.3.19.1 * xwayland-debugsource-24.1.5-150700.3.19.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1266294 * https://bugzilla.suse.com/show_bug.cgi?id=1266295 * https://bugzilla.suse.com/show_bug.cgi?id=1266296 * https://bugzilla.suse.com/show_bug.cgi?id=1266297 * https://bugzilla.suse.com/show_bug.cgi?id=1266298 * https://bugzilla.suse.com/show_bug.cgi?id=1266299 * https://bugzilla.suse.com/show_bug.cgi?id=1266300 * https://bugzilla.suse.com/show_bug.cgi?id=1266301
Attachment: None (type=text/html)
(HTML attachment elided)
