Important: xorg-x11-server security, bug fix, and enhancement update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:26610", "synopsis": "Important: xorg-x11-server security, bug fix, and enhancement update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for xorg-x11-server.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.\n\nSecurity Fix(es):\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256)\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257)\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258)\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259)\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260)\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261)\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262)\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263)\n\n* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264)\n\nBug Fix(es) and Enhancement(s):\n\n* [xserver] Backport other securityfixes without a CVE assigned [rhel-9.8.z] (JIRA:Rocky Linux-184288)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2485380", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485380", "description": ""}, {"ticket": "2485382", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485382", "description": ""}, {"ticket": "2485383", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485383", "description": ""}, {"ticket": "2485384", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485384", "description": ""}, {"ticket": "2485385", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485385", "description": ""}, {"ticket": "2485386", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485386", "description": ""}, {"ticket": "2485387", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485387", "description": ""}, {"ticket": "2485388", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485388", "description": ""}, {"ticket": "2485389", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2485389", "description": ""}], "cves": [{"name": "CVE-2026-50256", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50256", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-121"}, {"name": "CVE-2026-50257", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50257", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}, {"name":"CVE-2026-50258", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50258", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-121"}, {"name": "CVE-2026-50259", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50259", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-121"}, {"name": "CVE-2026-50260", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50260", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}, {"name": "CVE-2026-50261", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50261", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}, {"name": "CVE-2026-50262", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50262", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "5.5", "cwe": "CWE-125"}, {"name": "CVE-2026-50263", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50263", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "5.5", "cwe": "CWE-416"}, {"name": "CVE-2026-50264", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50264", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-787"}], "references": [], "publishedAt": "2026-06-19T00:03:21.214998Z", "rpms": {"Rocky Linux 9": {"nvras": ["xorg-x11-server-Xorg-debuginfo-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-0:1.20.11-34.el9_8.2.src.rpm", "xorg-x11-server-common-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-common-0:1.20.11-34.el9_8.2.ppc64le.rpm","xorg-x11-server-common-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-common-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-debuginfo-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-debuginfo-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-debuginfo-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-debuginfo-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-debugsource-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-debugsource-0:1.20.11-34.el9_8.2.i686.rpm", "xorg-x11-server-debugsource-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-debugsource-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-debugsource-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-devel-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-devel-0:1.20.11-34.el9_8.2.i686.rpm", "xorg-x11-server-devel-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-devel-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-devel-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-source-0:1.20.11-34.el9_8.2.noarch.rpm", "xorg-x11-server-Xdmx-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xdmx-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xdmx-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xdmx-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-Xdmx-debuginfo-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xdmx-debuginfo-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xdmx-debuginfo-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xdmx-debuginfo-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-Xephyr-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xephyr-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xephyr-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xephyr-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-Xephyr-debuginfo-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xephyr-debuginfo-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xephyr-debuginfo-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xephyr-debuginfo-0:1.20.11-34.el9_8.2.x86_64.rpm","xorg-x11-server-Xnest-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xnest-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xnest-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xnest-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-Xnest-debuginfo-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xnest-debuginfo-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xnest-debuginfo-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xnest-debuginfo-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-Xorg-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xorg-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xorg-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xorg-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-Xorg-debuginfo-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xorg-debuginfo-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xorg-debuginfo-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xvfb-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xvfb-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xvfb-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xvfb-0:1.20.11-34.el9_8.2.x86_64.rpm", "xorg-x11-server-Xvfb-debuginfo-0:1.20.11-34.el9_8.2.aarch64.rpm", "xorg-x11-server-Xvfb-debuginfo-0:1.20.11-34.el9_8.2.ppc64le.rpm", "xorg-x11-server-Xvfb-debuginfo-0:1.20.11-34.el9_8.2.s390x.rpm", "xorg-x11-server-Xvfb-debuginfo-0:1.20.11-34.el9_8.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Explore the critical xorg-x11-server updates on Rocky Linux addressing several security issues and enhancing stability.. Rocky Linux xorg-x11-server updates, xorg security fixes, Linux buffer overflow patches. . Severity: Important. LinuxSecurity.com Team
Qemu: net: mcf_fec: infinite loop while receiving data in mcf_fec_receive [CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] Qemu: audio: memory leakage in es1370 device [CVE-2017-5526] oob access in cirrus bitblt copy [XSA-208, CVE-2017-2615]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-cdb53b04e0 2017-02-14 17:43:48.000991 -------------------------------------------------------------------------------- Name : xen Product : Fedora 25 Version : 4.7.1 Release : 7.fc25 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: Qemu: net: mcf_fec: infinite loop while receiving data in mcf_fec_receive [CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] Qemu: audio: memory leakage in es1370 device [CVE-2017-5526] oob access in cirrus bitblt copy [XSA-208, CVE-2017-2615] -------------------------------------------------------------------------------- References: [ 1 ] Bug #1414108 - CVE-2017-5525 Qemu: audio: memory leakage in ac97 device https://bugzilla.redhat.com/show_bug.cgi?id=1414108 [ 2 ] Bug #1414209 - CVE-2017-5526 Qemu: audio: memory leakage in es1370 device https://bugzilla.redhat.com/show_bug.cgi?id=1414209 [ 3 ] Bug #1418200 - CVE-2017-2615 Qemu: display: cirrus: oob access while doing bitblt copy backward mode https://bugzilla.redhat.com/show_bug.cgi?id=1418200 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade xen' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.