X.Org Server Patched for Dozen Vulnerabilities, Including Code Execution Risks
X.Org has released updates for its X server and Xwayland components, addressing twelve security vulnerabilities, nine of which could allow for arbitrary code execution.

X.Org has issued patches for a significant batch of twelve security vulnerabilities affecting its widely used X server and Xwayland components. The fixes are available in versions xorg-server 21.1.25 and xwayland-24.1.14. Of particular concern, nine of these flaws carry the potential for arbitrary code execution, while three others could lead to server crashes or sensitive information disclosure.
The majority of these vulnerabilities, ten in total, require an authenticated X client to be exploited. This means an attacker would need to already have a connection accepted by the server, limiting the attack vector to systems where an attacker has some level of access. However, the advisories for CVE-2026-93524 and CVE-2026-93536 do not specify this prerequisite, potentially indicating a broader risk.
Eleven of the twelve vulnerabilities impact both the X server and Xwayland. A notable exception is CVE-2026-93522, a heap buffer overflow flaw specifically within the Glamor component's CopyArea code on GPU-accelerated systems, which affects only Xwayland.
Delving into the nature of the bugs, seven are identified as buffer overflows or out-of-bounds writes. Three are use-after-free vulnerabilities, where the server attempts to access memory that has already been deallocated. Additionally, one flaw is a double free vulnerability, and another is an out-of-bounds read.
Two of the patched vulnerabilities are noted as addressing incomplete fixes from previous efforts. CVE-2026-93520 stems from an earlier commit (a3171732d) that did not fully resolve the issue. Similarly, CVE-2026-93521 revisits a bug pattern previously fixed in the RandR output path, indicating that the provider path for this functionality was not adequately secured.
Specific extensions are required for certain vulnerabilities to be exploitable. For instance, CVE-2026-93515 relies on the Present and SYNC extensions, while CVE-2026-93519 requires XFIXES, XTEST, and more than 100 active pointer barriers.
Users running the X server or Xwayland are strongly advised to check their installed versions and upgrade to xorg-server 21.1.25 or xwayland-24.1.14, respectively. Each CVE entry in the advisory provides a direct link to the fix commit on the freedesktop.org GitLab repository for detailed technical information.
This extensive patching highlights the ongoing security challenges within core graphical components of Linux and other Unix-like operating systems. Maintaining the security of the X server, a foundational piece of many desktop environments, remains critical for system integrity and user data protection.