Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:38502: Important: xorg-x11-server-Xwayland security update

  • What: Security update for xorg-x11-server-Xwayland in Red Hat Enterprise Linux 8
  • Impact: Addresses stack overflow vulnerability in X server
Read Full Article →

Red Hat Product Errata RHSA-2026:38502 - Security Advisory Issued: 2026-07-13 Updated: 2026-07-13 RHSA-2026:38502 - Security Advisory Overview Updated Packages Synopsis Important: xorg-x11-server-Xwayland security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for xorg-x11-server-Xwayland is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Xwayland is an X server for running X clients under Wayland. Security Fix(es): xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2485380 - CVE-2026-50256 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch BZ - 2485382 - CVE-2026-50257 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() BZ - 2485383 - CVE-2026-50258 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels BZ - 2485384 - CVE-2026-50259 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing BZ - 2485385 - CVE-2026-50260 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() BZ - 2485386 - CVE-2026-50261 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() BZ - 2485387 - CVE-2026-50262 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes BZ - 2485388 - CVE-2026-50263 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() BZ - 2485389 - CVE-2026-50264 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat CVEs CVE-2026-50256 CVE-2026-50257 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262 CVE-2026-50263 CVE-2026-50264 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM xorg-x11-server-Xwayland-21.1.3-13.el8_8.1.src.rpm SHA-256: b637259064518d0b9d0268cf7ecd4643aa0afe88aa5ec8bc7607f57696104036 x86_64 xorg-x11-server-Xwayland-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 9cccd333320f926318d058b0b0bdefcb59011c29442320de6f98c8bb170271e8 xorg-x11-server-Xwayland-debuginfo-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 3fa792128dfba2f334c52863b7ac8edffef0601652959b8076a717f577ce82a6 xorg-x11-server-Xwayland-debugsource-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 8694cea601a8659da74866b8208e4f23669cd4e4b93386f2a7a2e7fe07754616 Red Hat Enterprise Linux Server - TUS 8.8 SRPM xorg-x11-server-Xwayland-21.1.3-13.el8_8.1.src.rpm SHA-256: b637259064518d0b9d0268cf7ecd4643aa0afe88aa5ec8bc7607f57696104036 x86_64 xorg-x11-server-Xwayland-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 9cccd333320f926318d058b0b0bdefcb59011c29442320de6f98c8bb170271e8 xorg-x11-server-Xwayland-debuginfo-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 3fa792128dfba2f334c52863b7ac8edffef0601652959b8076a717f577ce82a6 xorg-x11-server-Xwayland-debugsource-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 8694cea601a8659da74866b8208e4f23669cd4e4b93386f2a7a2e7fe07754616 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM xorg-x11-server-Xwayland-21.1.3-13.el8_8.1.src.rpm SHA-256: b637259064518d0b9d0268cf7ecd4643aa0afe88aa5ec8bc7607f57696104036 ppc64le xorg-x11-server-Xwayland-21.1.3-13.el8_8.1.ppc64le.rpm SHA-256: 119ef9dde5c134dacafe4bdc0f1fafd5c830d38d79c999f07c24f5214f4e8fc6 xorg-x11-server-Xwayland-debuginfo-21.1.3-13.el8_8.1.ppc64le.rpm SHA-256: 764337ebb71c690e304c55a0096671baa57c9bff645c2cf2bc913343492dae94 xorg-x11-server-Xwayland-debugsource-21.1.3-13.el8_8.1.ppc64le.rpm SHA-256: b61656c79818aba670bf6f3affc64ad3e3cbe8d1b789ae3397ea2b6bca45ec41 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM xorg-x11-server-Xwayland-21.1.3-13.el8_8.1.src.rpm SHA-256: b637259064518d0b9d0268cf7ecd4643aa0afe88aa5ec8bc7607f57696104036 x86_64 xorg-x11-server-Xwayland-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 9cccd333320f926318d058b0b0bdefcb59011c29442320de6f98c8bb170271e8 xorg-x11-server-Xwayland-debuginfo-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 3fa792128dfba2f334c52863b7ac8edffef0601652959b8076a717f577ce82a6 xorg-x11-server-Xwayland-debugsource-21.1.3-13.el8_8.1.x86_64.rpm SHA-256: 8694cea601a8659da74866b8208e4f23669cd4e4b93386f2a7a2e7fe07754616 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article