Red Hat Security Advisory: xorg-x11-server security, bug fix, and enhancement update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-50256 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch CVE-2026-50257 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() CVE-2026-50258 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels CVE-2026-50259 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing CVE-2026-50260 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() CVE-2026-50261 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() CVE-2026-50262 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes CVE-2026-50263 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() CVE-2026-50264 — xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:26709
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485382
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485384
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485385
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485389
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_26709.json