[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6370-1] xorg-server security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6370-1] xorg-server security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Sat, 27 Jun 2026 09:29:38 +0000 Message-id: <[🔎] E1wdPM2-00000005AuN-0JnY@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6370-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 27, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xorg-server CVE ID : CVE-2026-50256 CVE-2026-50257 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262 CVE-2026-50263 CVE-2026-50264 Debian Bug : 1138680 Several vulnerabilities were discovered in the Xorg X server, which may result in privilege escalation if the X server is running privileged. For the stable distribution (trixie), these problems have been fixed in version 2:21.1.16-1.3+deb13u3. We recommend that you upgrade your xorg-server packages. For the detailed security status of xorg-server please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xorg-server Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmo/l81fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Tdpw//aVN9oQn6/eQQrAZzVzGy4SGeu1GUGbapMVFtdxIGc7LOSifYvXkCK1tY NzbhBu0+3WZmzN1bE0VC3wiIiViKkl3jFZ26XpmU0dX02IYeB/FEdI9KxvJh7IG5 jfPBp8xGJPwdgWzZyG3lqoulXQ+jzU3QjdboNh3mSvh2rPHhVuPgoP3H5Uu+kWD1 DgyOk9kFa0vCw0Imp2f27OESTc2y8bARsRUQuNKcDtI9OoTYgnMfB6Jrq0q1QSc5 0BiWdOyAG6leJ9e0XEdyl4PfPymdkF+sGqm7ynQJlFGFen5tpCHpGm/BbGI1Hsao 2RBNga2suMaC4HXvBRIlh351RSM++xr1lwxk5XupFCNcdnYd0W1/P0l1glp3f5Xs /+Nh0KytXCxV4gckVF1gZz7c+K9yDX0zkNpVeNw3gppdmkwuTa/7Qx1Sfxhq5EhC C5bAR4/Gwk9cLeO59iJbHx+ktVe6tIPkiumwlB3kZSu29fUMrjcbLxKwOCJBWyDy 9wmKatWCLugizEcH7xoloTEdhbUmEgdMhrriV0PZ5DjhmT8RTbH4rpVrq0T3AIhB 3Yc92nWnuZZ959hLH3qeGBkwWOA1ZrWS2+3p1IDJsWesLPb2csF3e315zaj4c+Rm WsT21pMyZF04i63kwlB6QZQ7Y/Wq7l7ORXlWbIpX+yUQEDyZ71U= =ZHPC -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6370-1] incus security update Previous by thread: [SECURITY] [DSA 6370-1] incus security update Index(es): Date Thread
Multiple high-severity vulnerabilities (CVE-2026-50256 through CVE-2026-50264, CVSS 7.8) in the Xorg X server could lead to privilege escalation when the server runs with elevated privileges. The vulnerabilities affect X.Org Server versions prior to 21.1.23 and XWayland versions prior to 24.1.12. The Debian security advisory recommends upgrading the `xorg-server` packages to version 2:21.1.16-1.3+deb13u3 for the stable distribution.