Description:
Xwayland is an X server for running X clients under Wayland.
Security Fix(es):
* xorg: xwayland: X.Org X server: Denial of Service via integer underflow in XKB compatibility map handling (CVE-2026-33999)
* xorg: xwayland: X.Org X server: Use-after-free vulnerability leads to server crash and potential memory corruption (CVE-2026-34001)
* xorg: xwayland: X.Org X server: Information exposure and denial of service via out-of-bounds memory access (CVE-2026-34003)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
xorg-x11-server-Xwayland-devel-24.1.9-4.el9_8.aarch64.rpm |
813a6bb6ea32bd4c54b5d125685e3176a4072b46c7315fd704f8affe73bd398b |
| aarch64 |
xorg-x11-server-Xwayland-24.1.9-4.el9_8.aarch64.rpm |
9f7ae528ca4d6425d1e776af9b8c17b4a1d0d783bf14944365989d968b80692e |
| i686 |
xorg-x11-server-Xwayland-24.1.9-4.el9_8.i686.rpm |
87295b0240d28a7265c3a7ac29df4c0c4c28fb39264173f5d16c8625294c05c4 |
| i686 |
xorg-x11-server-Xwayland-devel-24.1.9-4.el9_8.i686.rpm |
e834b81f1dec898f760eb7dcf4d85c8f225743e4b3882a50465da6cde501b98c |
| ppc64le |
xorg-x11-server-Xwayland-devel-24.1.9-4.el9_8.ppc64le.rpm |
3b9c0a36364b853641518e0b85f86d3eb1e990cdd0c8b670f808ffa7cece2fd0 |
| ppc64le |
xorg-x11-server-Xwayland-24.1.9-4.el9_8.ppc64le.rpm |
7511c967d51300b6f5d138fb7329b993cba78ab58036bfd33d03bd1a28a86c2e |
| s390x |
xorg-x11-server-Xwayland-devel-24.1.9-4.el9_8.s390x.rpm |
53066d085e7e008b95a2327e86cda5da7bd31c43097330a86c62e66d4a613ce3 |
| s390x |
xorg-x11-server-Xwayland-24.1.9-4.el9_8.s390x.rpm |
5f0e669d4bdcaa1d13ca3c87ad069d11bf76b30ec204e4c2fd647df5b67b3af1 |
| x86_64 |
xorg-x11-server-Xwayland-devel-24.1.9-4.el9_8.x86_64.rpm |
e05b6759e71545a91f32b26464ccdb3165d7b53fc52795d8b0519064f68ca717 |
| x86_64 |
xorg-x11-server-Xwayland-24.1.9-4.el9_8.x86_64.rpm |
e348a32ab86dc703e5d1050ae98a21ab6c1e7079d26772e78ca0b2a70870a74c |