X.Org patches 12 vulnerabilities in X server and Xwayland
X.Org fixed 12 security flaws in the X server and Xwayland, shipping fixes in xorg-server 21.1.25 and xwayland-24.1.14. Nine flaws can lead to arbitrary code execution, while the other three can crash the server or disclose information.
- Fixes ship in xorg-server 21.1.25 and xwayland-24.1.14
- 9 of 12 flaws allow arbitrary code execution
- 11 flaws affect both X server and Xwayland
- CVE-2026-93522 is a Glamor buffer overflow in Xwayland only
Read next
Security