Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Mageia 9 x11-server Security Flaw - Buffer Overflow and Use-after-free

mageia
Calendar Grey May 26, 2026
Dist Mageia Esm H88
Updated x11-server and tigervnc packages mitigate multiple significant vulnerabilities identified in Mageia 9.
MGASA-2026-0155 - Updated x11-server, x11-server-xwayland & tigervnc packages fix security vulnerabilities

Summary

Description: XKB Integer Underflow in XkbSetCompatMap(). (CVE-2026-33999) XKB Out-of-bounds Read in CheckSetGeom(). (CVE-2026-34000) XSYNC Use-after-free in miSyncTriggerFence(). (CVE-2026-34001) XKB Out-of-bounds read in CheckModifierMap(). (CVE-2026-34002) XKB Buffer overflow in CheckKeyTypes(). (CVE-2026-34003)

References

- https://bugs.mageia.org/show_bug.cgi?id=35366

- https://www.openwall.com/lists/oss-security/2026/04/14/8

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JGQLR43Z7T6IISLCOC2Q4WB3D4YWB4QS/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RULWKTYNOMHH3NTJ36SDNJVWKXYJ4VVO/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33999

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34000

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34001

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34002

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34003

Resolution

SRPMS

- 9/core/x11-server-21.1.8-7.10.mga9

- 9/core/x11-server-xwayland-22.1.9-1.10.mga9

- 9/core/tigervnc-1.13.1-2.11.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 26 May 2026
URL: https://advisories.mageia.org/MGASA-2026-0155.html
Type: security
CVE: CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, CVE-2026-34003

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here