Debian Xwayland vulnerabilities
46 known vulnerabilities affecting debian/xwayland.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH39MEDIUM5LOW1
Vulnerabilities
Page 2 of 3
CVE-2023-0494P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-1 (bookworm)2023
CVE-2023-0494 [HIGH] CVE-2023-0494: xorg-server - A vulnerability was found in X.Org. This issue occurs due to a dangling pointer ...
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Sc
debian
CVE-2024-9632P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u8 (bookworm)2024
CVE-2024-9632 [HIGH] CVE-2024-9632: xorg-server - A flaw was found in the X.org server. Due to improperly tracked allocation size ...
A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.
Scope: local
bookworm: resolved (fix
debian
CVE-2023-5367P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u2 (bookworm)2023
CVE-2023-5367 [HIGH] CVE-2023-5367: xorg-server - A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs d...
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
Scope: loc
debian
CVE-2021-4009P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.13-3 (bookworm)2021
CVE-2021-4009 [HIGH] CVE-2021-4009: xorg-server - A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14...
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 2:1.20.13-3)
bullseye: resolved (fixed in 2
debian
CVE-2021-4010P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.13-3 (bookworm)2021
CVE-2021-4010 [HIGH] CVE-2021-4010: xorg-server - A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14...
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 2:1.20.13-3)
bullseye: resolved (fixed in 2:1.20.11
debian
CVE-2021-4008P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.13-3 (bookworm)2021
CVE-2021-4008 [HIGH] CVE-2021-4008: xorg-server - A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14...
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 2:1.20.13-3)
bullseye: resolved (fixed in 2:1.20
debian
CVE-2021-4011P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.13-3 (bookworm)2021
CVE-2021-4011 [HIGH] CVE-2021-4011: xorg-server - A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14...
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 2:1.20.13-3)
bullseye: resolved (fixed in 2:1.20.11-1+de
debian
CVE-2025-26597P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26597 [HIGH] CVE-2025-26597: xorg-server - A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey()...
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size.
Scope: local
bookworm: reso
debian
CVE-2025-26596P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26596 [HIGH] CVE-2025-26596: xorg-server - A heap overflow flaw was found in X.Org and Xwayland. The computation of the len...
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u9)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u15)
forky: resolved (fixed in 2:21.1.16-1)
sid: reso
debian
CVE-2025-62230P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u11 (bookworm)2025
CVE-2025-62230 [HIGH] CVE-2025-62230: xorg-server - A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when ha...
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
Scope: local
bookworm: resolved (fixed in 2:21
debian
CVE-2022-2319P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.4-1 (bookworm)2022
CVE-2022-2319 [HIGH] CVE-2022-2319: xorg-server - A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur...
A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length.
Scope: local
bookworm: resolved (fixed in 2:21.1.4-1)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u2)
forky: resolved (fixed in 2:21.1.4-1)
sid: resolved (fixed in 2:21.1.4-1)
trixie: resolved (fixe
debian
CVE-2025-26594P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26594 [HIGH] CVE-2025-26594: xorg-server - A use-after-free flaw was found in X.Org and Xwayland. The root cursor is refere...
A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u9)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u15)
forky: resolved (f
debian
CVE-2025-26600P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26600 [HIGH] CVE-2025-26600: xorg-server - A use-after-free flaw was found in X.Org and Xwayland. When a device is removed ...
A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u9)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u15)
forky: resolved (fixed in 2:21.1.
debian
CVE-2025-49179P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u10 (bookworm)2025
CVE-2025-49179 [HIGH] CVE-2025-49179: xorg-server - A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients...
A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u10)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u16)
forky: resolved (fixed in 2:21.1.16-1.2)
si
debian
CVE-2025-26601P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26601 [HIGH] CVE-2025-26601: xorg-server - A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, t...
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing a use-after
debian
CVE-2024-31080P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u7 (bookworm)2024
CVE-2024-31080 [HIGH] CVE-2024-31080: xorg-server - A heap-based buffer over-read vulnerability was found in the X.org server's Proc...
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attac
debian
CVE-2024-31081P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u7 (bookworm)2024
CVE-2024-31081 [HIGH] CVE-2024-31081: xorg-server - A heap-based buffer over-read vulnerability was found in the X.org server's Proc...
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attac
debian
CVE-2025-62229P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u11 (bookworm)2025
CVE-2025-62229 [HIGH] CVE-2025-62229: xorg-server - A flaw was found in the X.Org X server and Xwayland when processing X11 Present ...
A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.
Sco
debian
CVE-2025-26599P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26599 [HIGH] CVE-2025-26599: xorg-server - An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The ...
An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized po
debian
CVE-2024-0409P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u5 (bookworm)2024
CVE-2024-0409 [HIGH] CVE-2024-0409: xorg-server - A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwaylan...
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u5)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u11)
debian