X.Org fixed 12 security flaws in xorg-server 21.1.25 and xwayland 24.1.14, including nine bugs that could lead to code execution. Most of the issues can be triggered by an authenticated X client, meaning a program already allowed to talk to the display server.
The bugs are memory-corruption errors: buffer overflows, out-of-bounds writes, use-after-free, a double free, and an out-of-bounds read. One exception stands out: CVE-2026-93522 is a Glamor heap buffer overflow in GPU-accelerated Xwayland, so the riskiest case is a desktop stack that uses Xwayland with GPU acceleration and trusts local GUI clients too broadly.
For workstation fleets, the exposure sits in the display server itself, not just in individual apps. If a local or compromised X client can reach that server, a flaw there can disrupt or take over the graphical session; the Xwayland-only bug narrows the highest-risk path to GPU-accelerated setups.
Rilasciati aggiornamenti di sicurezza per X server, componente fondamentale del sistema grafico utilizzato in numerosi ambienti Unix e Linux, e per Xwayland, livello di compatibilità che consente l'esecuzione di applicazioni X11 in ambienti Wayland.