xorg-x11-server-1.20.11-34.el9_8.2

エラータID: AXSA:2026-1354:12

Release date: 
Monday, July 27, 2026 - 21:27
Subject: 
xorg-x11-server-1.20.11-34.el9_8.2
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.

Security Fix(es):

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264)

Bug Fix(es) and Enhancement(s):

* [xserver] Backport other security fixes without a CVE assigned [rhel-9.8.z] (JIRA:RHEL-184288)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-50256
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50257
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50258
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50259
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50260
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50261
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50262
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
CVE-2026-50263
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
CVE-2026-50264
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. xorg-x11-server-1.20.11-34.el9_8.2.src.rpm
    MD5: e02ca503029771cb03ca90524f77c089
    SHA-256: 4be61085d2cda1acb0be69ee427967eff8cd49ddf304a6a62da21c16ecdcbe04
    Size: 6.38 MB

Asianux Server 9 for x86_64
  1. xorg-x11-server-common-1.20.11-34.el9_8.2.x86_64.rpm
    MD5: 7d14149f1ad03a918aca7ac52f5e41b6
    SHA-256: 10bf7ed2a5b2a53d5c31b4f8c01501af6383cc3721df8a3ff76abfc54a21ed34
    Size: 34.09 kB
  2. xorg-x11-server-devel-1.20.11-34.el9_8.2.i686.rpm
    MD5: e266de8ad22b4e052522b1a1cc39e889
    SHA-256: 3ed9111248ba4ea899dc4c9b810ae7872ec4905013693c6e28c7a4b914aca577
    Size: 251.86 kB
  3. xorg-x11-server-devel-1.20.11-34.el9_8.2.x86_64.rpm
    MD5: 285600092ce064e406188aa30959a0ee
    SHA-256: a591340b00171f27e890204b48e918ba196bf7c3587d9b058ca98e276cd04541
    Size: 251.85 kB
  4. xorg-x11-server-source-1.20.11-34.el9_8.2.noarch.rpm
    MD5: bd5bf995fe765a5d3d9f563c832be100
    SHA-256: 851a3f3d2f226ea614db82582dab07fd7e496f6000b9b009b685dcb0b4326ad5
    Size: 2.37 MB
  5. xorg-x11-server-Xdmx-1.20.11-34.el9_8.2.x86_64.rpm
    MD5: 8a0099dc99424d3f7aec503809f5294b
    SHA-256: 7aaf4ecc4c2e01c99241b246da79e109cc300384a7fb69b0d3eec7c5e9695aab
    Size: 901.23 kB
  6. xorg-x11-server-Xephyr-1.20.11-34.el9_8.2.x86_64.rpm
    MD5: aab108749200b5f7f73cc08a4fa4358e
    SHA-256: 0880c3cca80c117da5a4a4ac5b424ad64afbd1cdea31f0d2b90eaf0ad2db8fc8
    Size: 1.02 MB
  7. xorg-x11-server-Xnest-1.20.11-34.el9_8.2.x86_64.rpm
    MD5: c402daa184fea4c04022e6876631a0c7
    SHA-256: edc88d3f90ed3d8cea824344585ccccc726eb2ab7acf0e2cedf2bbca6f8cba64
    Size: 719.04 kB
  8. xorg-x11-server-Xorg-1.20.11-34.el9_8.2.x86_64.rpm
    MD5: 7deb94c0873bcdb40c9b0c78aa043fa6
    SHA-256: b09141704afff419d54151a3f3acbaf6070836a56dc6bc5b4ec85bee29688ce4
    Size: 1.46 MB
  9. xorg-x11-server-Xvfb-1.20.11-34.el9_8.2.x86_64.rpm
    MD5: f83db68072924a1f012a1e7c07346058
    SHA-256: f478848db48d2174717a210f09f7066ff275857a8b4a6d01633d3630c091c054
    Size: 895.63 kB