|
|
Log in / Subscribe / Register

Red Hat alert RHSA-2026:26562-01 (xorg-x11-server-Xwayland)

An update for xorg-x11-server-Xwayland is now available for Red Hat
Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

Xwayland is an X server for running X clients under Wayland.

Security Fix(es):

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer
overflow in font alias resolution due to libXfont2 name length mismatch
(CVE-2026-50256)

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free
in miSyncDestroyFence() (CVE-2026-50257)

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer
overflow in XKB key types due to unchecked shift levels (CVE-2026-50258)

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer
overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259)

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free
in FreeCounter() (CVE-2026-50260)

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free
in SyncChangeCounter() (CVE-2026-50261)

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds
read/write in GLX ChangeDrawableAttributes (CVE-2026-50262)

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free
information disclosure in CreateSaverWindow() (CVE-2026-50263)

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds
heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264)

Bug Fix(es) and Enhancement(s):

* [xwayland] Backport other security fixes without a CVE assigned
[rhel-8.10.z] (JIRA:RHEL-184293)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

This content is licensed under the Creative Commons Attribution 4.0
International License (https://creativecommons.org/licenses/by/4.0/). If you
distribute this content, or a modified version of it, you must provide
attribution to Red Hat Inc. and provide a link to the original.

Original: https://access.redhat.com/security/data/csaf/v2/advisories/2026/rhsa-2026_26562.json


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds