[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6497-1] xorg-server security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6497-1] xorg-server security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Sat, 12 Sep 2026 11:48:46 +0000 Message-id: <[🔎] E1x5MDu-000000003em-0x3m@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6497-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 12, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xorg-server CVE ID : CVE-2026-55999 CVE-2026-56000 Debian Bug : 1141703 Several vulnerabilities were discovered in the Xorg X server, which may result in privilege escalation if the X server is running privileged. For the stable distribution (trixie), these problems have been fixed in version 2:21.1.16-1.3+deb13u4. We recommend that you upgrade your xorg-server packages. For the detailed security status of xorg-server please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xorg-server Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqlO+tfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0TbGw/+O7Ex9BSUreel3GVuPiPvFoJkxS/NLJTxhjWE+NJR14Q4OJA78fhcax5K Y3GDs6WcaGi0CI9koLlXyfiSTDnEpm+HllKwsfQxcNMrijvGLXyMirv1oKo33CVV NIdDN3CpwB/rGQstKrMmo30w0BHh1fEjxE+1Hl41OwTzJSfdAGBuBWXsP9atomrO 7MGLWGDh7WwXTDdgqmCYB1mUelT1/bLXkq1Rv5SMiGm2R8/4NEWkAsuAiLhQGBTT tH4QFxaR/xIWwOrNVyWLBTW6SfnNClkLz6JpOrfSqWbDQhM5smOt3IiPjIbNmUol VByK++FN3b77/a99JudL8bQvuI5KTi7iD0az5oBsCjrt4Ka6HzCZf5bDfHEVJTvW 2uUPgrQ7l7/SQUVRuEu/ZT4VLUT1R+7N632O2S0v0Jc8YXcNtDedbMZf8VWtM5lT 0/WBpDRtSpP4tqOl8QfCGIgll7PS1/EkiL+OSih6+697GE1dF7heKDz3TWXDc9rT Kuonpo2GdFXWUSiJzGXROazMpTz+7qSrr9InpSlMkzWyAjohSlFZyd5F87xznhQY uDOxg7S63m6yjPGiDgTRkij5YOYCVfB5IW69NmDZhi9VSBslnJAhAfjCbqYDCWs2 qC3zCIB793UPEEMyn1mQj3OY1r1dVJt/lhorLsAWWTOg/saygsU= =G8v4 -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6496-1] nginx security update Previous by thread: [SECURITY] [DSA 6496-1] nginx security update Index(es): Date Thread
Multiple vulnerabilities (CVE-2026-55999 and CVE-2026-56000, both rated HIGH with CVSS scores of 8.5 and 7.8 respectively) in the Xorg X server could lead to privilege escalation when the server runs with elevated privileges. The vulnerabilities affect x.org X Server versions prior to 21.2.24 and x.org XWayland versions prior to 24.1.13. The fix requires upgrading to xorg-server version 2:21.1.16-1.3+deb13u4 for Debian stable (trixie), which corresponds to upstream patched versions 21.2.24 and 24.1.13.