12 New CVEs in X.Org Server and XWayland

The X.Org project has released a security advisory covering twelve new vulnerabilities in the X server and XWayland. The fixes are out in xorg-server 21.1.25 and xwayland 24.1.14. Almost all of the findings came through Trend Micro's Zero Day Initiative, which found them with the help of AI.

The twelve CVEs

Most of the bugs are memory-safety issues in XKB, GLX, RandR, XFixes, XInput, Present, and glamor:

What this means for you

Most of the bugs are triggerable by an authenticated X client. A compromised or specially crafted client can therefore crash the X server or, depending on the vulnerability, potentially execute code or read memory contents. The advisory itself draws these lines carefully: some issues are crash bugs, two can leak memory contents, and the rest range up to potential code execution.

For Wayland systems, XWayland is the relevant part: if you run X11 applications through XWayland, you still have an X server process on your system, and that process is what these fixes are for. Systems that run no X11 applications at all have no exposed X server code.

The twelve bugs are overwhelmingly memory-safety issues: use-after-frees, a double free, buffer overflows, and out-of-bounds reads and writes. That is the same class of problem the X server has been producing for decades, and this batch shows how much faster such patterns can now be found.

The fixes are in the release announcements. Check whether a security update for X.Org Server or XWayland is already available for your distribution. The package version does not have to match the upstream versions 21.1.25 and 24.1.14, because distributions frequently backport security fixes without adopting the upstream version number.

One more detail for those tracking the development branch: the release candidates for the upcoming 26.1.0 line contain the twelve fixes as well, including xorg-server 26.0.99.903, the third RC.

The full advisory with technical details and fix commits is on the X.Org announcement list, and the source lives in the xserver repository.