X.Org disclosed nine security vulnerabilities in the X server and Xwayland and released fixes in xorg-server 21.1.23 and xwayland 24.1.12. The bugs, later assigned CVE-2026-50256 through CVE-2026-50264, affect versions prior to those releases and span multiple subsystems including libXfont2/font alias handling, XSYNC, XKB, GLX, screensaver code, and DRI2. Reported impacts include crashes, information disclosure, memory corruption, and possible privilege escalation where the X server runs as root; some reports also note potential remote code execution exposure in environments using SSH X11 forwarding. Most issues were reported by an anonymous researcher working with TrendAI Zero Day Initiative, while one DRI2 flaw was credited to Peter Hutterer of Red Hat.
The fixes address several distinct bug classes: a stack-based buffer overflow caused by a font-name length mismatch during alias resolution, multiple use-after-free conditions in XSYNC object teardown and CreateSaverWindow, stricter GLX request-size validation to stop malformed client requests from reaching unsafe paths, and DRI2 hardening to validate and deduplicate buffer attachments before allocation and processing. One disclosed flaw, tracked as CVE-2026-50256, allows any client able to connect to the server to trigger a font-alias overflow that could lead to denial of service or elevated impact on root-run servers. Red Hat separately rated affected X.Org server packages as Important across supported RHEL releases, underscoring the need to update exposed X.Org and Xwayland deployments.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
A Red Hat Bugzilla entry documented CVE-2026-50256 as a stack buffer overflow in font alias resolution caused by a font-name length mismatch, noting potential denial of service or privilege escalation and linking the fix to xorg-server 21.1.23 and xwayland 24.1.12.
By June 5, 2026, the previously disclosed X.Org and Xwayland issues had been assigned CVE-2026-50256 through CVE-2026-50264. Earlier disclosure notes had said CVEs were requested but not yet assigned.
X.Org announced xwayland 24.1.12 to remediate the same set of security issues affecting earlier Xwayland releases.
X.Org announced xorg-server 21.1.23 as the security update that fixes the disclosed vulnerabilities in affected X server versions.
On June 2, 2026, X.Org disclosed multiple security issues affecting X.Org X server versions before 21.1.23 and Xwayland versions before 24.1.12. The advisory described stack overflows, use-after-free bugs, out-of-bounds access, and an information disclosure issue across several components.
A defensive DRI2 patch added attachment bounds checking, deduplication, and safer buffer-handling logic in do_get_buffers to prevent invalid attachment processing and related memory misuse.
A patch added bounds checks in font-handling routines to reject oversized font names before copying them into buffers, addressing unsafe handling of long alias target names.
X.Org committed a fix for a use-after-free in CreateSaverWindow by re-fetching the screen private after CheckScreenPrivate. The flaw could be triggered through a specific screensaver attribute and activation sequence and was reported via TrendAI Zero Day Initiative.
A patch hardened XSYNC cleanup logic in FreeCounter and related code to avoid unsafe trigger handling during object destruction, addressing memory-safety risks such as use-after-free.
A source-code change tightened GLX request handlers by replacing permissive length checks with exact-size validation, reducing exposure to malformed client requests in ChangeDrawableAttributes and related paths.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcelists.x.org
Open sourceaccess.redhat.com
Open sourcelists.x.org
Open sourceopennet.me
Open sourceopennet.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.