Multiple vulnerabilities have been found in X.Org X server, XWayland. Affected packages Package x11-base/xorg-server on all architectures Affected versions < 21.1.24 Unaffected versions >= 21.1.24 Package x11-base/xwayland on all architectures Affected versions < 24.1.13 Unaffected versions >= 24.1.13 Background The X Window System is a graphical windowing system based on a client/server model. Description Multiple vulnerabilities have been discovered in X.Org X server, XWayland. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All X.Org X server, XWayland users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=x11-base/xorg-server-21.1.24" All X.Org X server, XWayland users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=x11-base/xwayland-24.1.13" References CVE-2025-49175 CVE-2025-49176 CVE-2025-49177 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180 CVE-2025-62229 CVE-2025-62230 CVE-2025-62231 CVE-2026-33999 CVE-2026-34000 CVE-2026-34001 CVE-2026-34002 CVE-2026-34003 CVE-2026-50256 CVE-2026-50257 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262 CVE-2026-50263 CVE-2026-55999 CVE-2026-56000 Release date August 17, 2026 Latest revision August 17, 2026: 1 Severity high Exploitable remote Bugzilla entries 958340 965271 972712 976628 978969
Multiple vulnerabilities in X.Org X server and XWayland, detailed across numerous CVEs including CVE-2025-49176 (CVSS 7.3 HIGH), pose a significant security risk. Affected versions are xorg-server < 21.1.24 and xwayland < 24.1.13. A full resolution requires upgrading to xorg-server version 21.1.24 and xwayland version 24.1.13, as no workaround is currently available.