Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:38488: Important: xorg-x11-server-Xwayland security update

A heap buffer overflow in the glamor Font Atlas of the X.Org Xwayland server (CVE-2026-55999, CVSS 8.5 HIGH) could allow for potential code execution. The vulnerability affects X.Org X Server versions prior to 21.2.24 and Xwayland versions prior to 24.1.13. Red Hat has issued an Important security update for xorg-x11-server-Xwayland in RHEL 8 to address this flaw.
Read Full Article →

Red Hat Product Errata RHSA-2026:38488 - Security Advisory Issued: 2026-07-13 Updated: 2026-07-13 RHSA-2026:38488 - Security Advisory Overview Updated Packages Synopsis Important: xorg-x11-server-Xwayland security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for xorg-x11-server-Xwayland is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Xwayland is an X server for running X clients under Wayland. Security Fix(es): xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow (CVE-2026-55999) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2496165 - CVE-2026-55999 xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow CVEs CVE-2026-55999 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.src.rpm SHA-256: b5b148f0faff9a8004fd918a5c0d5601ea81619d268d24f577db9fb4c6e6b0e4 x86_64 xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.x86_64.rpm SHA-256: 2cd875b8540ecfe1c84ba201ff014438bf8a254228b532ad323c92b6a426668c xorg-x11-server-Xwayland-debuginfo-21.1.3-20.el8_10.3.x86_64.rpm SHA-256: 156f689951df38cf408942fb5eaa3f0fab4f97260a6b657e016beb6d017ea77c xorg-x11-server-Xwayland-debugsource-21.1.3-20.el8_10.3.x86_64.rpm SHA-256: 11c222bada7234b3715a742ec2900f6ebdc764111a56d04e6778b93d350c1990 Red Hat Enterprise Linux for IBM z Systems 8 SRPM xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.src.rpm SHA-256: b5b148f0faff9a8004fd918a5c0d5601ea81619d268d24f577db9fb4c6e6b0e4 s390x xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.s390x.rpm SHA-256: 19c78c085e479970969e4ec46b990febd8dbf2348a4424eff8c0107e14d9904f xorg-x11-server-Xwayland-debuginfo-21.1.3-20.el8_10.3.s390x.rpm SHA-256: 1514d2ffb4189c499ef675ff1dc80fa57bd94b94c6fc31bdd419070adc429261 xorg-x11-server-Xwayland-debugsource-21.1.3-20.el8_10.3.s390x.rpm SHA-256: 64e1d2bb673c81f7647d98f2b3eba908f5d55e2bbf4c691ffe9288606e84f051 Red Hat Enterprise Linux for Power, little endian 8 SRPM xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.src.rpm SHA-256: b5b148f0faff9a8004fd918a5c0d5601ea81619d268d24f577db9fb4c6e6b0e4 ppc64le xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.ppc64le.rpm SHA-256: 2f44e96d45f000ef7928eaeeca52fce8d08b95aadb6a6f3c047ed7d4a7459b8e xorg-x11-server-Xwayland-debuginfo-21.1.3-20.el8_10.3.ppc64le.rpm SHA-256: 6360717ca2b9c75584c925d5dbd684ff63adf29c0a35735e7d11ec749749b47c xorg-x11-server-Xwayland-debugsource-21.1.3-20.el8_10.3.ppc64le.rpm SHA-256: 2e2dfe8045c38b18e8c18006f5a47edb658f6e1bde67b06d6560695dbd349c15 Red Hat Enterprise Linux for ARM 64 8 SRPM xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.src.rpm SHA-256: b5b148f0faff9a8004fd918a5c0d5601ea81619d268d24f577db9fb4c6e6b0e4 aarch64 xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.aarch64.rpm SHA-256: 0385874f9304ad161cfd3004c757f777d2490a03ba04743422f4896b610a74d6 xorg-x11-server-Xwayland-debuginfo-21.1.3-20.el8_10.3.aarch64.rpm SHA-256: f7bf005f74aaeb8080586fb423a7197d5ddccc1073a703e51f0481de75a0a2b8 xorg-x11-server-Xwayland-debugsource-21.1.3-20.el8_10.3.aarch64.rpm SHA-256: a693abd79a0551c5b33fc16590c058c44d0a880fb0d7d13eecc9efccae3f91e3 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.src.rpm SHA-256: b5b148f0faff9a8004fd918a5c0d5601ea81619d268d24f577db9fb4c6e6b0e4 x86_64 xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.x86_64.rpm SHA-256: 2cd875b8540ecfe1c84ba201ff014438bf8a254228b532ad323c92b6a426668c xorg-x11-server-Xwayland-debuginfo-21.1.3-20.el8_10.3.x86_64.rpm SHA-256: 156f689951df38cf408942fb5eaa3f0fab4f97260a6b657e016beb6d017ea77c xorg-x11-server-Xwayland-debugsource-21.1.3-20.el8_10.3.x86_64.rpm SHA-256: 11c222bada7234b3715a742ec2900f6ebdc764111a56d04e6778b93d350c1990 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.src.rpm SHA-256: b5b148f0faff9a8004fd918a5c0d5601ea81619d268d24f577db9fb4c6e6b0e4 aarch64 xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.aarch64.rpm SHA-256: 0385874f9304ad161cfd3004c757f777d2490a03ba04743422f4896b610a74d6 xorg-x11-server-Xwayland-debuginfo-21.1.3-20.el8_10.3.aarch64.rpm SHA-256: f7bf005f74aaeb8080586fb423a7197d5ddccc1073a703e51f0481de75a0a2b8 xorg-x11-server-Xwayland-debugsource-21.1.3-20.el8_10.3.aarch64.rpm SHA-256: a693abd79a0551c5b33fc16590c058c44d0a880fb0d7d13eecc9efccae3f91e3 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.src.rpm SHA-256: b5b148f0faff9a8004fd918a5c0d5601ea81619d268d24f577db9fb4c6e6b0e4 ppc64le xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.ppc64le.rpm SHA-256: 2f44e96d45f000ef7928eaeeca52fce8d08b95aadb6a6f3c047ed7d4a7459b8e xorg-x11-server-Xwayland-debuginfo-21.1.3-20.el8_10.3.ppc64le.rpm SHA-256: 6360717ca2b9c75584c925d5dbd684ff63adf29c0a35735e7d11ec749749b47c xorg-x11-server-Xwayland-debugsource-21.1.3-20.el8_10.3.ppc64le.rpm SHA-256: 2e2dfe8045c38b18e8c18006f5a47edb658f6e1bde67b06d6560695dbd349c15 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 SRPM xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.src.rpm SHA-256: b5b148f0faff9a8004fd918a5c0d5601ea81619d268d24f577db9fb4c6e6b0e4 s390x xorg-x11-server-Xwayland-21.1.3-20.el8_10.3.s390x.rpm SHA-256: 19c78c085e479970969e4ec46b990febd8dbf2348a4424eff8c0107e14d9904f xorg-x11-server-Xwayland-debuginfo-21.1.3-20.el8_10.3.s390x.rpm SHA-256: 1514d2ffb4189c499ef675ff1dc80fa57bd94b94c6fc31bdd419070adc429261 xorg-x11-server-Xwayland-debugsource-21.1.3-20.el8_10.3.s390x.rpm SHA-256: 64e1d2bb673c81f7647d98f2b3eba908f5d55e2bbf4c691ffe9288606e84f051 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article