Opened 3 months ago
Closed 2 months ago
#23576 closed enhancement (fixed)
xwayland-24.1.13
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
This release contains the fixes for the issues reported in today's
security advisory:
https://lists.x.org/archives/xorg-announce/2026-July/003716.html
- CVE-2026-55999: glamor Font Atlas Heap Buffer Overflow
- CVE-2026-56000: GLX contextTags Use-After-Free in CommonMakeCurrent()
In addition we have a few other smaller cleanup fixes.
Mikhail Dmitrichenko (1):
xkb: preserve buffer on realloc failure
Olivier Fourdan (4):
dix: Silence a compiler warning in doListFontsAndAliases()
dix: Silent static analyzer warning
dix: Silence a compiler warning in doListFontsWithInfo()
Xi: Check window attribute is valid in XIChangeCursor
Peter Hutterer (7):
dix/colormap: fix out-of-bounds read in FindColorInRootCmap
glx: fix duplicate tagInfo->vendor = NULL assignment
glamor: fix an error path cleanup
glx: free old context tag before allocating new one in CommonMakeCurrent
fb/mi/glamor: reject glyphs with negative dimensions
glamor: reject fonts with per-glyph metrics exceeding maxbounds
Bump version to 24.1.13
git tag: xwayland-24.1.13
Change History (3)
comment:1 by , 3 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 3 months ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
comment:3 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-156 has been issued.
Note:
See TracTickets
for help on using tickets.

Fixed at 470ba562c5. Leaving open for SA.