xorg-x11-server-Xwayland-21.1.3-20.el8_10.2
エラータID: AXSA:2026-805:03
以下項目について対処しました。
[Security Fix]
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50256)
- X.org、および Xwayland の miSyncDestroyFence() 関数には、
メモリ領域の解放後利用の問題があるため、ローカルの攻撃者により、
サービス拒否攻撃 (クラッシュの発生)、および特権昇格を可能とする
脆弱性が存在します。(CVE-2026-50257)
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50258)
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50259)
- X.Org、および Xwayland には、メモリ領域の解放後利用の問題が
あるため、ローカルの攻撃者により、サービス拒否攻撃 (クラッシュの
発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50260)
- X.Org、および Xwayland の SyncChangeCounter() 関数には、
メモリ領域の解放後利用の問題があるため、ローカルの攻撃者により、
サービス拒否攻撃 (クラッシュの発生)、および特権昇格を可能とする
脆弱性が存在します。(CVE-2026-50261)
- X.Org、および Xwayland の __glXDisp_ChangeDrawableAttributes()
関数には、メモリ領域の範囲外読み取りの問題があるため、ローカルの
攻撃者により、情報の漏洩を可能とする脆弱性が存在します。
(CVE-2026-50262)
- X.Org、および Xwayland の CreateSaverWindow() 関数には、メモリ
領域の解放後利用の問題があるため、ローカルの攻撃者により、情報の
漏洩を可能とする脆弱性が存在します。(CVE-2026-50263)
- X.Org、および Xwayland には、メモリ領域の範囲外書き込みの問題
があるため、ローカルの攻撃者により、サービス拒否攻撃 (クラッシュ
の発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50264)
パッケージをアップデートしてください。
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
N/A
SRPMS
- xorg-x11-server-Xwayland-21.1.3-20.el8_10.2.src.rpm
MD5: b1111c4e20b7492d246c3800b07c2fbb
SHA-256: 76ceedc36a651497c22d8bb089116b748ed0da330205ba36bfd423137d45bcab
Size: 1.32 MB
Asianux Server 8 for x86_64
- xorg-x11-server-Xwayland-21.1.3-20.el8_10.2.x86_64.rpm
MD5: 4d18fb40a733bbf9e0955ffdad1eca12
SHA-256: 0830c17cd8ecf26fccdfa8a09ab87cecde8c3709a960a1ac83a79f0ab2868055
Size: 968.89 kB