xorg-x11-server-Xwayland-24.1.9-4.el9_8.2
エラータID: AXSA:2026-1355:07
以下項目について対処しました。
[Security Fix]
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50256)
- X.org、および Xwayland の miSyncDestroyFence() 関数には、
メモリ領域の解放後利用の問題があるため、ローカルの攻撃者により、
サービス拒否攻撃 (クラッシュの発生)、および特権昇格を可能とする
脆弱性が存在します。(CVE-2026-50257)
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50258)
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50259)
- X.Org、および Xwayland には、メモリ領域の解放後利用の問題が
あるため、ローカルの攻撃者により、サービス拒否攻撃 (クラッシュの
発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50260)
- X.Org、および Xwayland の SyncChangeCounter() 関数には、
メモリ領域の解放後利用の問題があるため、ローカルの攻撃者により、
サービス拒否攻撃 (クラッシュの発生)、および特権昇格を可能とする
脆弱性が存在します。(CVE-2026-50261)
- X.Org、および Xwayland の __glXDisp_ChangeDrawableAttributes()
関数には、メモリ領域の範囲外読み取りの問題があるため、ローカルの
攻撃者により、情報の漏洩を可能とする脆弱性が存在します。
(CVE-2026-50262)
- X.Org、および Xwayland の CreateSaverWindow() 関数には、メモリ
領域の解放後利用の問題があるため、ローカルの攻撃者により、情報の
漏洩を可能とする脆弱性が存在します。(CVE-2026-50263)
- X.Org、および Xwayland には、メモリ領域の範囲外書き込みの問題
があるため、ローカルの攻撃者により、サービス拒否攻撃 (クラッシュ
の発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50264)
パッケージをアップデートしてください。
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
N/A
SRPMS
- xorg-x11-server-Xwayland-24.1.9-4.el9_8.2.src.rpm
MD5: 7f68114983f8b86c71e89e8b318b9f9f
SHA-256: a901c891f6136d8f019419678ca4e97451a86594022885d29d03a18b66ed0dd2
Size: 1.31 MB
Asianux Server 9 for x86_64
- xorg-x11-server-Xwayland-24.1.9-4.el9_8.2.i686.rpm
MD5: d17046596c5a725078b1ec527b70e625
SHA-256: f1839834391329c6dd5b5c16237e70d4acf8df4b3bfde4341315ccd81e895973
Size: 1.02 MB - xorg-x11-server-Xwayland-24.1.9-4.el9_8.2.x86_64.rpm
MD5: 9851e936ad4c0c46663ad6f54a5f457e
SHA-256: b56b3bd8be66eb5975358c41d3ec4577bec5c90e84c5e9129a1a100ba7d0f922
Size: 0.98 MB - xorg-x11-server-Xwayland-devel-24.1.9-4.el9_8.2.i686.rpm
MD5: 8db7b34121aae4ecd8aae8aaa7764cdb
SHA-256: d68e6f01fa09034a263e7cbdb70468fbe74b3cc5448e7ebe6493d87cf41651d5
Size: 9.33 kB - xorg-x11-server-Xwayland-devel-24.1.9-4.el9_8.2.x86_64.rpm
MD5: 3e81934ba9d68d31d0d7dfe764c38096
SHA-256: 69309a6a0b2fc567d94e7b7ec7c3a9322f54f8b0399c2488d61e1288062b28c8
Size: 9.30 kB