[ GLSA 202608-14 ] X.Org X server, XWayland: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178694848756.1.9778795871217493063@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: X.Org X server, XWayland: Multiple Vulnerabilities
     Date: August 17, 2026
     Bugs: #958340, #965271, #972712, #976628, #978969
       ID: 202608-14

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in X.Org X server, XWayland.

Background
==========

The X Window System is a graphical windowing system based on a
client/server model.

Affected packages
=================

Package               Vulnerable    Unaffected
--------------------  ------------  ------------
x11-base/xorg-server  < 21.1.24     >= 21.1.24
x11-base/xwayland     < 24.1.13     >= 24.1.13

Description
===========

Multiple vulnerabilities have been discovered in X.Org X server,
XWayland. Please review the CVE identifiers referenced below for
details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All X.Org X server, XWayland users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=x11-base/xorg-server-21.1.24"

All X.Org X server, XWayland users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=x11-base/xwayland-24.1.13"

References
==========

[ 1 ] CVE-2025-49175
      https://nvd.nist.gov/vuln/detail/CVE-2025-49175
[ 2 ] CVE-2025-49176
      https://nvd.nist.gov/vuln/detail/CVE-2025-49176
[ 3 ] CVE-2025-49177
      https://nvd.nist.gov/vuln/detail/CVE-2025-49177
[ 4 ] CVE-2025-49178
      https://nvd.nist.gov/vuln/detail/CVE-2025-49178
[ 5 ] CVE-2025-49179
      https://nvd.nist.gov/vuln/detail/CVE-2025-49179
[ 6 ] CVE-2025-49180
      https://nvd.nist.gov/vuln/detail/CVE-2025-49180
[ 7 ] CVE-2025-62229
      https://nvd.nist.gov/vuln/detail/CVE-2025-62229
[ 8 ] CVE-2025-62230
      https://nvd.nist.gov/vuln/detail/CVE-2025-62230
[ 9 ] CVE-2025-62231
      https://nvd.nist.gov/vuln/detail/CVE-2025-62231
[ 10 ] CVE-2026-33999
      https://nvd.nist.gov/vuln/detail/CVE-2026-33999
[ 11 ] CVE-2026-34000
      https://nvd.nist.gov/vuln/detail/CVE-2026-34000
[ 12 ] CVE-2026-34001
      https://nvd.nist.gov/vuln/detail/CVE-2026-34001
[ 13 ] CVE-2026-34002
      https://nvd.nist.gov/vuln/detail/CVE-2026-34002
[ 14 ] CVE-2026-34003
      https://nvd.nist.gov/vuln/detail/CVE-2026-34003
[ 15 ] CVE-2026-50256
      https://nvd.nist.gov/vuln/detail/CVE-2026-50256
[ 16 ] CVE-2026-50257
      https://nvd.nist.gov/vuln/detail/CVE-2026-50257
[ 17 ] CVE-2026-50258
      https://nvd.nist.gov/vuln/detail/CVE-2026-50258
[ 18 ] CVE-2026-50259
      https://nvd.nist.gov/vuln/detail/CVE-2026-50259
[ 19 ] CVE-2026-50260
      https://nvd.nist.gov/vuln/detail/CVE-2026-50260
[ 20 ] CVE-2026-50261
      https://nvd.nist.gov/vuln/detail/CVE-2026-50261
[ 21 ] CVE-2026-50262
      https://nvd.nist.gov/vuln/detail/CVE-2026-50262
[ 22 ] CVE-2026-50263
      https://nvd.nist.gov/vuln/detail/CVE-2026-50263
[ 23 ] CVE-2026-55999
      https://nvd.nist.gov/vuln/detail/CVE-2026-55999
[ 24 ] CVE-2026-56000
      https://nvd.nist.gov/vuln/detail/CVE-2026-56000

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-14

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqCq4cbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZggMP/jI0lRFgODFBw5/CVd8E
vuIYCaDGpgGgOFqxy3WpBfjKNZ/8a6s5D6ybSB7Jd4lLhZzo/UGlc8UjPrxt90HN
02f9EOZtHnToT4X8LSalDTIOTIcnpkHJWgdQ/4niIG7iPuanHtnmsjQzVBhxzzGy
ZJTB40US6HzmwsZtPif3NzqjXgScjxEq7FvC6YLWgmUejVd33VqrXewzdzdFGSW+
oQsXEDMWVtg5F17L1LiS+meQnQeoW13q8YCjz/lD82JDhlD1jn49Nce869NEIpq2
56s3uXNVHzAbwAqPTKus16QoWQ2hhKc1JvdgYlsfmqxMX47YDYlWK7hHc2UwotqK
dd9fXPUUW/ikp4pxikTnYaS8iL2+088N8y1K1u/qeQaCgprHgFQNyfPD/qK5rMIf
E97eRFhyWevq1G7pqT3V/mHSjjkaw4ywVZmI/Jjz3qkWZ64/hvjd0QYFCjAX7KaT
1P4k0tgFrCfpIXTDgeiPqC1ytS9+yPyfg0gzfcc34jM/HaOiHYGn1sSKcZyJ5npM
RPzUhf/fuOyxIeGaeKmAFd/tmG6fdV43bGJEvlMLaqnx1uK2HMSAQk5AbcouJRQC
EbEUzkc0CRq4UHqtmlAKqVeZsvVfgwMr6OFISipQTC8wUidFsKHzZOLrEE+ihtDE
oCwiRoPwV87iqdn/cMtlIrfz
=QdHS
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.