X.Org Releases xorg-server 21.1.25 and XWayland 24.1.14 Security Fixes
The updates patch six CVEs that let authenticated X clients trigger double free, use-after-free and heap buffer overflows.
X.Org has released xorg-server 21.1.25 and XWayland 24.1.14 to address several security issues, according to gamingonlinux.com. The two updates patch a set of vulnerabilities tracked as CVE-2026-88812, CVE-2026-93515, CVE-2026-93516, CVE-2026-93517, CVE-2026-93518 and CVE-2026-93519.
The flaws allow authenticated X clients to trigger conditions including double free, use-after-free and heap buffer overflows. Such issues can potentially lead to arbitrary code execution or denial of service.
Users are advised to watch for updates from their Linux distribution to receive the fixes. Distribution maintainers package the patched X.Org code, so the corrected versions will arrive through the usual update channels rather than from a single download.
Quick answers
What versions fix these X.Org security issues?
xorg-server 21.1.25 and XWayland 24.1.14 contain the fixes.
Which CVEs are addressed?
The releases address CVE-2026-88812, CVE-2026-93515, CVE-2026-93516, CVE-2026-93517, CVE-2026-93518 and CVE-2026-93519.
How do I get the updates?
Users are advised to watch for updates from their Linux distribution.