-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 24 Jun 2026 14:06:35 +0200 Source: xorg-server Architecture: source Version: 2:21.1.16-1.3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 1138680 Changes: xorg-server (2:21.1.16-1.3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * sync: fix deletion of counters and fences (CVE-2026-50257, CVE-2026-50260) (Closes: #1138680) * sync: restart trigger list iteration in SyncChangeCounter after TriggerFired (CVE-2026-50261) (Closes: #1138680) * xkb: reject key types with num_levels exceeding XkbMaxShiftLevel (CVE-2026-50258) (Closes: #1138680) * xkb: clamp nMaps to mapWidths buffer size in CheckKeyTypes (CVE-2026-50259) (Closes: #1138680) * glx: fix reversed length check in ChangeDrawableAttributes (CVE-2026-50262) (Closes: #1138680) * saver: re-fetch screen private after CheckScreenPrivate in CreateSaverWindow (CVE-2026-50263) (Closes: #1138680) * dix: increase XLFDMAXFONTNAMELEN to match libXfont2's MAXFONTNAMELEN (CVE-2026-50256) (Closes: #1138680) * dri2: Use booleans for (fake) front buffer tracking in do_get_buffers (CVE-2026-50264) (Closes: #1138680) * dri2: Deduplicate attachments in do_get_buffer (CVE-2026-50264) (Closes: #1138680) Checksums-Sha1: cd078c5a46d5b16783ea55691e918bc755f3c54f 4236 xorg-server_21.1.16-1.3+deb13u3.dsc b59502b070fb042562b0f2a18b9e2f17d5dd8ae9 204441 xorg-server_21.1.16-1.3+deb13u3.diff.gz 44c71eb72d3e629ec99ed6fbdf919c7e9dd99859 8480 xorg-server_21.1.16-1.3+deb13u3_source.buildinfo Checksums-Sha256: 291d236d3318de7ec4ca19275d1810fc405aa402b13c441b071754d736ce1d7e 4236 xorg-server_21.1.16-1.3+deb13u3.dsc 79df2421354c8890d41f207f18423a84ba3298e6be2970f2baba2a58d4b84abb 204441 xorg-server_21.1.16-1.3+deb13u3.diff.gz 6d64cc629ed70805947082712f4c0109ce8ec9d2aa0b8702b4e8b39acfa5c5f0 8480 xorg-server_21.1.16-1.3+deb13u3_source.buildinfo Files: 8410cec3143a91b2744fe0d90cf9afe9 4236 x11 optional xorg-server_21.1.16-1.3+deb13u3.dsc fb7ed8380d22a357ee7050c8f4627cbb 204441 x11 optional xorg-server_21.1.16-1.3+deb13u3.diff.gz bd700b75c23d0df55356e2307334450f 8480 x11 optional xorg-server_21.1.16-1.3+deb13u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmo8JvNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89E1aoP/0Npcio7or2cOvwxQCccDvnGziP/wUea gnmivqgPIbQ29FXSnyJBmCCA1eFQ0N4b27o7YpXfduBNYzJwhGGHKARFVvfyU98u gzS9XAlz8kjZtcbtS6SFTjcC+TXMGa7r+qbgXyG5SOdURQHWV0Qoc7tEbV4YOEjg vkTuiNmh35OHOcbDO33GeyDtIgRgXpuYsd4JNUbOoM0v0uHVTKO3YfQEMcyw3sJi 6q7PpgfdJdiElyjpUN1IauvgOOmUPWxY+gG1LxMT0UQ/fu+f0cbK8BnixRCcXr6D bLA6XOd2P4faX2wCDDuxmE0L3r9XVQ3PVbLbAnUBXacHrTsVw8+S39ty/7o4U+jM x0j5EA5imjvCl3btkSg4IfLUch5FOwQhfpXIRjTWb9ClRybKQ/s2go3q5oAFM5TO VVqeNB1MnH8NsLaX81+RC8hseQ3ULMhWuJdt1WKMILthZsIU67TRrXT9Y8vVqjXn OVvmqJQgxfK7VShuVvc07D02iWSRwhU9zvUNGFzD5hmarQ5881+iNHt7cRCMHAWZ fTGHeOWC4ekPp5ynqgqg/XGo/azVNprXOWf7MuH3cYdMYuRBbf2+FNgthUUgngtS pbRg2Wt3ajzZcQ6TTWdZLUXES21BdFSSlIayn+O7TLGXNCLKQ7pWzeoyT0N1rCJ/ 7oEJfoky6Y0+ =v2xT -----END PGP SIGNATURE-----