Opened 6 months ago
Closed 6 months ago
#23144 closed enhancement (fixed)
xorg-server-21.1.22
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
https://lists.x.org/archives/xorg-announce/2026-April/003677.html
======================================================================
X.Org Security Advisory: April 14, 2026
Issues in X.Org X server prior to 21.1.22 and Xwayland prior to 24.1.10
======================================================================
Multiple issues have been found in the X server and Xwayland implementations
published by X.Org for which we are releasing security fixes for in
xorg-server-21.1.22 and xwayland-24.1.10.
* CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap()
If a "compat" buffer was previously truncated, there will be unused
space left in the buffer. The code in XkbSetCompatMap() will use that
space, but fails to update the number of valid entries actually in the
buffer.
As a result, that can lead to buffer read overrun when processing a
future request.
Introduced in: Prior to X11R6.6 Xorg baseline
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b024ae17
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
* CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom()
Each key alias entry contains two key names (the alias and the real
key name).
The code in CheckSetGeom() does its bounds checking using only the
first name, allowing XkbAddGeomKeyAlias to read uninitialised memory.
Introduced in: xorg-server-21.1.4 and xwayland-22.1.3
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/81b6a34f
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
* CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence()
When walking the list of fences to trigger, miSyncTriggerFence() may
call TriggerFence() for the current trigger, which end up calling the
function SyncAwaitTriggerFired().
SyncAwaitTriggerFired() frees the entire await resource, which removes
all triggers from that await, including the next entries in the list
of fences, leading to a use-after-free.
Introduced in: xorg-server-1.9.0
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f19ab94b
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
* CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap()
CheckModifierMap() reads from the wire in a loop without verifying that
the data remains within the bounds of the client request.
As a result, the total number of keys could exceed the actual data
provided, causing a potential read of uninitialised memory.
Introduced in: Prior to X11R6.6 Xorg baseline
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f056ce1c
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
* CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes()
The function CheckKeyTypes() will loop over the client's request but
won't perform any additional bound checking to ensure that the data
read remains within the request bounds.
As a result, a specifically crafted request may cause CheckKeyTypes()
to read uninitialised memory past the request data.
Introduced in: Prior to X11R6.6 Xorg baseline
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b85b00dd
https://gitlab.freedesktop.org/xorg/xserver/-/commit/d38c563f
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
------------------------------------------------------------------------
Change History (5)
comment:1 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 6 months ago
comment:3 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:4 by , 6 months ago
| Owner: | changed from to |
|---|
Note:
See TracTickets
for help on using tickets.

This release contains the fixes for the issues reported in today's security advisory: https://lists.x.org/archives/xorg-announce/2026-April/003677.html * CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap() * CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom() * CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence() * CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap() * CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes() Additionally, it contains a number of other various fixes from the stable xserver-21.1-branch: Alan Coopersmith (17): Create a SECURITY.md file Makefile.am: add SECURITY.md to EXTRA_DIST xfree86: Fix builds with gcc -Wpedantic dix: set errorValue correctly when XID lookup fails in ChangeGCXIDs() os: include <assert.h> in ospoll.c os: make FormatInt64() handle LONG_MIN correctly xf86bigfont: fix -Wimplicit-function-declaration error dix: Fix builds with meson -Dxace=false -Dwerror=true meson: don't build xselinux if xace is disabled glamor: handle potential NULL return from GetPictureScreenIfSet() glamor: handle allocation failure in glamor_create_pixmap() glamor: silence false positive in glamor_validate_gc() glamor: handle allocation failures in glamor_largepixmap.c glamor: avoid null dereference in glamor_dash_setup() glamor: avoid null dereference in glamor_composite_clipped_region() glamor: avoid double free in glamor_make_pixmap_exportable() os: fix sha1 build error with Nettle 4.0 Alexander Melnyk (1): xkb: Fix locked/latched indicator desync across multiple keyboards Benjamin Valentin (1): xf86: check return value of XF86_CRTC_CONFIG_PTR in xf86CompatOutput() Jeremy Huddleston Sequoia (4): rootless: Fix Glyphs damage bounding box to correctly compute union rootless: Add Trapezoids, Triangles, and CompositeRects wrapping rootless: Protect alpha channel for Render operations xquartz: Bump copyrights in Info.plist to 2026 Matthieu Herrb (1): Better fix for xf86CompatOut() when there are no privates Mikhail Dmitrichenko (3): os: avoid closing null fd at Fopen render: fix multiple mem leaks on err paths dix: avoid null ptr deref at doListFontsAndAliases Olivier Fourdan (6): xkb: Fix bounds check in _CheckSetGeom() miext/sync: Fix use-after-free in miSyncTriggerFence() xkb: Fix out-of-bounds read in CheckModifierMap() xkb: Add additional bound checking in CheckKeyTypes() xkb: Add more _XkbCheckRequestBounds() xserver 21.1.22 Peter Harris (1): xkb: fix buffer re-use in _XkbSetCompatMap Pierre Le Marre (2): xkb: Fix key type without level names in XkbCopyKeymap xkb: Fix serialization of key type without level names Takashi Yano (1): Fix mach64 driver crash Twaik Yont (1): os: use close-on-exec for X server socket to prevent fd leaks hongao (1): randr: clear primary screen's primaryOutput when the output is deleted quantenzitrone (2): COPYING: add missing paragraph to SGI-B-2.0 COPYING: add author to HPND-sell-MIT-disclaimer-xserver git tag: xorg-server-21.1.22Fixed at 1d6124e3aa. Leaving open for SA.