Opened 6 months ago
Closed 6 months ago
#23145 closed enhancement (fixed)
xwayland-24.1.10
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
https://lists.x.org/archives/xorg-announce/2026-April/003677.html
======================================================================
X.Org Security Advisory: April 14, 2026
Issues in X.Org X server prior to 21.1.22 and Xwayland prior to 24.1.10
======================================================================
Multiple issues have been found in the X server and Xwayland implementations
published by X.Org for which we are releasing security fixes for in
xorg-server-21.1.22 and xwayland-24.1.10.
* CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap()
If a "compat" buffer was previously truncated, there will be unused
space left in the buffer. The code in XkbSetCompatMap() will use that
space, but fails to update the number of valid entries actually in the
buffer.
As a result, that can lead to buffer read overrun when processing a
future request.
Introduced in: Prior to X11R6.6 Xorg baseline
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b024ae17
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
* CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom()
Each key alias entry contains two key names (the alias and the real
key name).
The code in CheckSetGeom() does its bounds checking using only the
first name, allowing XkbAddGeomKeyAlias to read uninitialised memory.
Introduced in: xorg-server-21.1.4 and xwayland-22.1.3
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/81b6a34f
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
* CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence()
When walking the list of fences to trigger, miSyncTriggerFence() may
call TriggerFence() for the current trigger, which end up calling the
function SyncAwaitTriggerFired().
SyncAwaitTriggerFired() frees the entire await resource, which removes
all triggers from that await, including the next entries in the list
of fences, leading to a use-after-free.
Introduced in: xorg-server-1.9.0
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f19ab94b
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
* CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap()
CheckModifierMap() reads from the wire in a loop without verifying that
the data remains within the bounds of the client request.
As a result, the total number of keys could exceed the actual data
provided, causing a potential read of uninitialised memory.
Introduced in: Prior to X11R6.6 Xorg baseline
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/f056ce1c
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
* CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes()
The function CheckKeyTypes() will loop over the client's request but
won't perform any additional bound checking to ensure that the data
read remains within the request bounds.
As a result, a specifically crafted request may cause CheckKeyTypes()
to read uninitialised memory past the request data.
Introduced in: Prior to X11R6.6 Xorg baseline
Fixed in: xorg-server-21.1.22 and xwayland-24.1.10
Fix: https://gitlab.freedesktop.org/xorg/xserver/-/commit/b85b00dd
https://gitlab.freedesktop.org/xorg/xserver/-/commit/d38c563f
Found by: Jan-Niklas Sohn working with TrendAI Zero Day Initiative.
------------------------------------------------------------------------
Change History (5)
comment:1 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 6 months ago
comment:3 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:4 by , 6 months ago
| Owner: | changed from to |
|---|
Note:
See TracTickets
for help on using tickets.

This release contains the fixes for the issues reported in today's security advisory: https://lists.x.org/archives/xorg-announce/2026-April/003677.html * CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap() * CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom() * CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence() * CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap() * CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes() Additionally, it contains a number of other various fixes from the stable xwayland-24.1 branch: Alan Coopersmith (18): xf86bigfont: fix -Wimplicit-function-declaration error dix: Fix builds with meson -Dxace=false -Dwerror=true meson: don't build xselinux if xace is disabled xwayland: fix builds with xace disabled panoramix: avoid null dereference in PanoramiXMaybeAddDepth() panoramix: avoid null dereference in PanoramiXConsolidate() glamor: handle potential NULL return from GetPictureScreenIfSet() glamor: handle allocation failure in glamor_create_pixmap() glamor: silence false positive in glamor_validate_gc() glamor: handle allocation failures in glamor_largepixmap.c glamor: avoid null dereference in glamor_dash_setup() glamor: avoid null dereference in glamor_composite_clipped_region() glamor: avoid double free in glamor_make_pixmap_exportable() Create a SECURITY.md file dix: set errorValue correctly when XID lookup fails in ChangeGCXIDs() os: make FormatInt64() handle LONG_MIN correctly os: fix sha1 build error with Nettle 4.0 os: include <assert.h> in ospoll.c Alexander Melnyk (1): xkb: Fix locked/latched indicator desync across multiple keyboards Liu Heng (2): xwayland: Fix incorrect pointer coordinates in enter events xwayland: prevent X11 get enter event when pointer is over Wayland client Michel Dänzer (3): xwayland: Update surface window from xwl_unrealize_window xwayland: Use WindowPtr for damage closure again Revert "xwayland: Call register_damage depending on ensure_surface_for_window" Mikhail Dmitrichenko (3): os: avoid closing null fd at Fopen render: fix multiple mem leaks on err paths dix: avoid null ptr deref at doListFontsAndAliases Olivier Fourdan (9): xwayland: Do not pretend leaving the X11 surface if buttons are down xwayland: Expunge the SECURITY.md file xwayland: Use viewport scale for warping coordinates xkb: Fix bounds check in _CheckSetGeom() miext/sync: Fix use-after-free in miSyncTriggerFence() xkb: Fix out-of-bounds read in CheckModifierMap() xkb: Add additional bound checking in CheckKeyTypes() xkb: Add more _XkbCheckRequestBounds() Bump version to 24.1.10 Peter Harris (1): xkb: fix buffer re-use in _XkbSetCompatMap Pierre Le Marre (2): xkb: Fix key type without level names in XkbCopyKeymap xkb: Fix serialization of key type without level names Twaik Yont (1): os: use close-on-exec for X server socket to prevent fd leaks Yixue Wang (1): xwayland: wrong expecting_event hongao (1): randr: clear primary screen's primaryOutput when the output is deleted quantenzitrone (2): COPYING: add missing paragraph to SGI-B-2.0 COPYING: add author to HPND-sell-MIT-disclaimer-xserver git tag: xwayland-24.1.10Fixed at 8842adde8b. Leaving open for SA.