Opened 6 months ago

Closed 6 months ago

#23144 closed enhancement (fixed)

xorg-server-21.1.22

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

​https://lists.x.org/archives/xorg-announce/2026-April/003677.html

======================================================================
X.Org Security Advisory: April 14, 2026

Issues in X.Org X server prior to 21.1.22 and Xwayland prior to 24.1.10
======================================================================

Multiple issues have been found in the X server and Xwayland implementations
published by X.Org for which we are releasing security fixes for in
xorg-server-21.1.22 and xwayland-24.1.10.


* CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap()
   
   If a "compat" buffer was previously truncated, there will be unused
   space left in the buffer. The code in XkbSetCompatMap() will use that
   space, but fails to update the number of valid entries actually in the
   buffer.

   As a result, that can lead to buffer read overrun when processing a
   future request.

   Introduced in: Prior to X11R6.6 Xorg baseline
   Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b024ae17
   Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.

* CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom()

   Each key alias entry contains two key names (the alias and the real
   key name).
     
   The code in CheckSetGeom() does its bounds checking using only the
   first name, allowing XkbAddGeomKeyAlias to read uninitialised memory.

   Introduced in: xorg-server-21.1.4 and xwayland-22.1.3
   Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/81b6a34f
   Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.

* CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence()

   When walking the list of fences to trigger, miSyncTriggerFence() may
   call TriggerFence() for the current trigger, which end up calling the
   function SyncAwaitTriggerFired().

   SyncAwaitTriggerFired() frees the entire await resource, which removes
   all triggers from that await, including the next entries in the list
   of fences, leading to a use-after-free.

   Introduced in: xorg-server-1.9.0
   Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f19ab94b
   Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.

* CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap()

   CheckModifierMap() reads from the wire in a loop without verifying that
   the data remains within the bounds of the client request.
     
   As a result, the total number of keys could exceed the actual data
   provided, causing a potential read of uninitialised memory.

   Introduced in: Prior to X11R6.6 Xorg baseline
   Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f056ce1c
   Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.

* CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes()

   The function CheckKeyTypes() will loop over the client's request but
   won't perform any additional bound checking to ensure that the data
   read remains within the request bounds.
     
   As a result, a specifically crafted request may cause CheckKeyTypes()
   to read uninitialised memory past the request data.

   Introduced in: Prior to X11R6.6 Xorg baseline
   Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
   Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b85b00dd
        https://gitlab.freedesktop.org/xorg/xserver/-/commit/d38c563f
   Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.

------------------------------------------------------------------------

Change History (5)

comment:1 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 6 months ago

This release contains the fixes for the issues reported in today's security
advisory: https://lists.x.org/archives/xorg-announce/2026-April/003677.html

    * CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap()
    * CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom()
    * CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence()
    * CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap()
    * CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes()

Additionally, it contains a number of other various fixes from the stable
xserver-21.1-branch:

Alan Coopersmith (17):
       Create a SECURITY.md file
       Makefile.am: add SECURITY.md to EXTRA_DIST
       xfree86: Fix builds with gcc -Wpedantic
       dix: set errorValue correctly when XID lookup fails in ChangeGCXIDs()
       os: include <assert.h> in ospoll.c
       os: make FormatInt64() handle LONG_MIN correctly
       xf86bigfont: fix -Wimplicit-function-declaration error
       dix: Fix builds with meson -Dxace=false -Dwerror=true
       meson: don't build xselinux if xace is disabled
       glamor: handle potential NULL return from GetPictureScreenIfSet()
       glamor: handle allocation failure in glamor_create_pixmap()
       glamor: silence false positive in glamor_validate_gc()
       glamor: handle allocation failures in glamor_largepixmap.c
       glamor: avoid null dereference in glamor_dash_setup()
       glamor: avoid null dereference in glamor_composite_clipped_region()
       glamor: avoid double free in glamor_make_pixmap_exportable()
       os: fix sha1 build error with Nettle 4.0

Alexander Melnyk (1):
       xkb: Fix locked/latched indicator desync across multiple keyboards

Benjamin Valentin (1):
       xf86: check return value of XF86_CRTC_CONFIG_PTR in xf86CompatOutput()

Jeremy Huddleston Sequoia (4):
       rootless: Fix Glyphs damage bounding box to correctly compute union
       rootless: Add Trapezoids, Triangles, and CompositeRects wrapping
       rootless: Protect alpha channel for Render operations
       xquartz: Bump copyrights in Info.plist to 2026

Matthieu Herrb (1):
       Better fix for xf86CompatOut() when there are no privates

Mikhail Dmitrichenko (3):
       os: avoid closing null fd at Fopen
       render: fix multiple mem leaks on err paths
       dix: avoid null ptr deref at doListFontsAndAliases

Olivier Fourdan (6):
       xkb: Fix bounds check in _CheckSetGeom()
       miext/sync: Fix use-after-free in miSyncTriggerFence()
       xkb: Fix out-of-bounds read in CheckModifierMap()
       xkb: Add additional bound checking in CheckKeyTypes()
       xkb: Add more _XkbCheckRequestBounds()
       xserver 21.1.22

Peter Harris (1):
       xkb: fix buffer re-use in _XkbSetCompatMap

Pierre Le Marre (2):
       xkb: Fix key type without level names in XkbCopyKeymap
       xkb: Fix serialization of key type without level names

Takashi Yano (1):
       Fix mach64 driver crash

Twaik Yont (1):
       os: use close-on-exec for X server socket to prevent fd leaks

hongao (1):
       randr: clear primary screen's primaryOutput when the output is deleted

quantenzitrone (2):
       COPYING: add missing paragraph to SGI-B-2.0
       COPYING: add author to HPND-sell-MIT-disclaimer-xserver

git tag: xorg-server-21.1.22

Fixed at 1d6124e3aa. Leaving open for SA.

comment:3 by Joe Locash, 6 months ago

Owner: changed from Joe Locash to Douglas R. Reno
Status: assigned → new

comment:4 by Bruce Dubbs, 6 months ago

Owner: changed from Douglas R. Reno to SecurityAdvisory

comment:5 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-048 issued.

Note: See TracTickets for help on using tickets.