Debian Package Tracker
Register | Log in
Subscribe

xwayland

X server for running X clients under Wayland

Choose email to subscribe with

general
  • source: xwayland (main)
  • version: 2:24.1.13-1
  • maintainer: Debian X Strike Force (archive) (DMD)
  • uploaders: Timo Aaltonen [DMD]
  • std-ver: 4.6.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 2:22.1.9-1
  • stable: 2:24.1.6-1
  • testing: 2:24.1.12-1
  • unstable: 2:24.1.13-1
versioned links
  • 2:22.1.9-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:24.1.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:24.1.12-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:24.1.13-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • xwayland (35 bugs: 0, 35, 0, 0)
action needed
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-55999: Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
  • CVE-2026-56000: Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
Created: 2026-07-08 Last update: 2026-08-05 17:01
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-08-09 00:00
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-06 Last update: 2026-08-06 16:19
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.0).
Created: 2022-05-11 Last update: 2026-08-05 18:00
No known security issue in trixie wishlist

There are 25 open security issues in trixie.

25 ignored issues:
  • CVE-2025-49175: A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.
  • CVE-2025-49176: A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
  • CVE-2025-49177: A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
  • CVE-2025-49178: A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.
  • CVE-2025-49179: A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.
  • CVE-2025-49180: A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocate.
  • CVE-2025-62229: A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.
  • CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
  • CVE-2025-62231: A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
  • CVE-2026-33999: A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.
  • CVE-2026-34000: A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.
  • CVE-2026-34001: A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.
  • CVE-2026-34002: A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service.
  • CVE-2026-34003: A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.
  • CVE-2026-50256: A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
  • CVE-2026-50257: A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
  • CVE-2026-50258: A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
  • CVE-2026-50259: A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
  • CVE-2026-50260: A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
  • CVE-2026-50261: A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
  • CVE-2026-50262: An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
  • CVE-2026-50263: A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
  • CVE-2026-50264: An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
  • CVE-2026-55999: Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
  • CVE-2026-56000: Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
Created: 2025-06-17 Last update: 2026-08-05 17:01
testing migrations
  • excuses:
    • Migration status for xwayland (2:24.1.12-1 to 2:24.1.13-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for flameshot/14.0.0-4: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, loong64: Test triggered, ppc64el: Pass, riscv64: Test triggered, s390x: Pass
    • ∙ ∙ Autopkgtest for gnome-settings-daemon/51~beta-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, loong64: Test triggered, ppc64el: Pass, riscv64: Test triggered, s390x: Failed (not a regression) ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for gnome-shell/50.2-3: s390x: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for gnome-shell/50.3-1: amd64: Pass, arm64: Regression ♻ (reference ♻), armhf: Pass, i386: Pass, loong64: Test triggered, ppc64el: Regression ♻ (reference ♻), riscv64: Test triggered
    • ∙ ∙ Autopkgtest for mir/2.28.0-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, loong64: Test triggered, ppc64el: Pass, riscv64: Test triggered, s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Autopkgtest for mutter/50.3-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, loong64: Test triggered, ppc64el: Pass, s390x: Pass
    • ∙ ∙ Autopkgtest for mutter/n/a: riscv64: Regression ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for reform-tools/1.87-1: s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Autopkgtest for reform-tools/1.88-1: amd64: No tests, superficial or marked flaky ♻, arm64: Pass, armhf: No tests, superficial or marked flaky ♻, i386: No tests, superficial or marked flaky ♻, loong64: Test triggered, ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), riscv64: Test triggered
    • ∙ ∙ Autopkgtest for weston/16.0.0-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, loong64: Test triggered, ppc64el: Pass, riscv64: Ignored failure ♻ (reference ♻), s390x: No tests, superficial or marked flaky ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for xwayland-run/0.0.5-1: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻, armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻, loong64: Test triggered, ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), riscv64: Test triggered, s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Too young, only 4 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/x/xwayland.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-08-05] Accepted xwayland 2:24.1.13-1 (source) into unstable (Emilio Pozuelo Monfort)
  • [2026-06-07] xwayland 2:24.1.12-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-02] Accepted xwayland 2:24.1.12-1 (source) into unstable (Timo Aaltonen)
  • [2026-05-03] xwayland 2:24.1.11-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-28] Accepted xwayland 2:24.1.11-1 (source) into unstable (Timo Aaltonen)
  • [2026-04-20] xwayland 2:24.1.10-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-14] Accepted xwayland 2:24.1.10-1 (source) into unstable (Timo Aaltonen)
  • [2025-11-30] xwayland 2:24.1.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-24] Accepted xwayland 2:24.1.9-1 (source) into unstable (Timo Aaltonen)
  • [2025-09-02] xwayland 2:24.1.8-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-27] Accepted xwayland 2:24.1.8-1 (source) into unstable (Timo Aaltonen)
  • [2025-03-03] xwayland 2:24.1.6-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-26] Accepted xwayland 2:24.1.6-1 (source) into unstable (Emilio Pozuelo Monfort)
  • [2025-02-12] xwayland 2:24.1.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-06] Accepted xwayland 2:24.1.5-1 (source) into unstable (Timo Aaltonen)
  • [2025-02-01] xwayland 2:24.1.4-3 MIGRATED to testing (Debian testing watch)
  • [2025-01-27] Accepted xwayland 2:24.1.4-3 (source) into unstable (Timo Aaltonen)
  • [2024-12-21] xwayland 2:24.1.4-2 MIGRATED to testing (Debian testing watch)
  • [2024-12-16] Accepted xwayland 2:24.1.4-2 (source) into unstable (Timo Aaltonen)
  • [2024-11-05] xwayland 2:24.1.4-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-31] Accepted xwayland 2:24.1.4-1 (source) into unstable (Timo Aaltonen)
  • [2024-10-21] xwayland 2:24.1.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-16] Accepted xwayland 2:24.1.3-1 (source) into unstable (Timo Aaltonen)
  • [2024-08-13] xwayland 2:24.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-08] Accepted xwayland 2:24.1.2-1 (source) into unstable (Timo Aaltonen)
  • [2024-05-23] xwayland 2:24.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-15] Accepted xwayland 2:24.1.0-1 (source) into unstable (Timo Aaltonen)
  • [2024-04-29] xwayland 2:23.2.6-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-26] Accepted xwayland 2:24.0.99.901-1 (source) into experimental (Timo Aaltonen)
  • [2024-04-13] Accepted xwayland 2:23.2.6-1 (source) into unstable (Timo Aaltonen)
  • 1
  • 2
bugs [bug history graph]
  • all: 35
  • RC: 0
  • I&N: 35
  • M&W: 0
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2:24.1.13-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing