<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:55:29.392625+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:26562</id>
    <title>ALSA-2026:26562 — Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update</title>
    <updated>2026-10-02T14:55:30.104972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: xorg-x11-server-Xwayland</p>
<p>Xwayland is an X server for running X clients under Wayland.</p>
<p>Security Fix(es):</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256)
  * xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257)
  * xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258)
  * xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259)
  * xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260)
  * xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261)
  * xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262)
  * xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263)
  * xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [xwayland] Backport other security fixes without a CVE assigned [almalinux-8.10.z] (JIRA:AlmaLinux-184293)</p>
<p>For more details…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:26562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08149</id>
    <title>bdu:2026-08149</title>
    <updated>2026-10-02T14:55:30.105060+00:00</updated>
    <content>bdu:2026-08149</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-50263</id>
    <title>BELL-CVE-2026-50263</title>
    <updated>2026-10-02T14:55:30.105078+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: xorg-server, Alpaquita:25: xorg-server, Alpaquita:stream: xorg-server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-50263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737</id>
    <title>certfr-2026-avi-0737 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T14:55:30.105101+00:00</updated>
    <content>certfr-2026-avi-0737</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-377488</id>
    <title>EUVD-2026-377488</title>
    <updated>2026-10-02T14:55:30.105117+00:00</updated>
    <content>EUVD-2026-377488</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-377488"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50263</id>
    <title>fkie_cve-2026-50263</title>
    <updated>2026-10-02T14:55:30.105128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4ph5-83mw-vm42</id>
    <title>GHSA-4ph5-83mw-vm42</title>
    <updated>2026-10-02T14:55:30.105150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4ph5-83mw-vm42"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-50263</id>
    <title>msrc_CVE-2026-50263 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()</title>
    <updated>2026-10-02T14:55:30.105165+00:00</updated>
    <content>msrc_CVE-2026-50263</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-50263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2681</id>
    <title>OESA-2026-2681 — xorg-x11-server security update</title>
    <updated>2026-10-02T14:55:30.105181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: xorg-x11-server, openEuler:24.03-LTS-SP3: xorg-x11-server, openEuler:20.03-LTS-SP4: xorg-x11-server, openEuler:22.03-LTS-SP4: xorg-x11-server</p>
<p>X.Org X11 X server

Security Fix(es):</p>
<p>[&amp;apos;Hi all,\n\nCVEs have been issued now, please see inline below\n\nOn Tue, Jun 02, 2026 at 10:01:46AM +1000, Peter Hutterer wrote:&amp;apos;, &amp;quot;=======================================================================\nX.Org Security Advisory: June 2, 2026 \n\nIssues in X.Org X server prior to 21.1.23 and Xwayland prior to 24.1.12\n=======================================================================\n\nMultiple issues have been found in the X server and Xwayland implementations\npublished by X.Org for which we are releasing security fixes for in\nxorg-server-21.1.23 and xwayland-24.1.12.\n\nNote that CVEs have been requested for these issues but did not get assigned in\ntime for this disclosure.\n\n* Font Alias Stack-based Buffer Overflow\n\n    A mismatch between the X server and the libXfont2 library&amp;apos;s maximum\n    font name length can cause a stack buffer overflow during font alias\n    resolution. The server allocates a 256 byte stack buffer but libXfont2&amp;apos;s\n    alias target name length is 1024 bytes. A font alias name between 257\n    and 1023 bytes causes the X server to copy that name into the undersized\n    stack buffer without further checks.\n\n    Fixed in: xorg-server-21.1.23 and xwayland-24.1.12\n    Fix:&amp;quot;, &amp;apos;Found by: Anonymous working with TrendAI Zero Day Initiative.\n              (ZDI-CAN-30136)&amp;apos;, &amp;apos;This issue has been assigned CVE-2026-50256&amp;apos;, &amp;apos;* XSYNC Use-After-Free in m…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2681"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26562</id>
    <title>RHSA-2026:26562 — Red Hat Security Advisory: xorg-x11-server-Xwayland security, bug fix, and enhancement update</title>
    <updated>2026-10-02T14:55:30.105293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:36083</id>
    <title>RHSA-2026:36083 — Red Hat Security Advisory: xorg-x11-server security update</title>
    <updated>2026-10-02T14:55:30.105339+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:36083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:26562</id>
    <title>RLSA-2026:26562 — Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update</title>
    <updated>2026-10-02T14:55:30.105373+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: xorg-x11-server-Xwayland</p>
<p>Xwayland is an X server for running X clients under Wayland.</p>
<p>Security Fix(es):</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256)</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257)</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258)</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259)</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260)</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261)</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262)</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263)</p>
<p>* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [xwayland] Backport other security fixes without a CVE assigned [rhel-8.10.z] (JIRA:Rocky Linux-184293)</p>
<p>For more details about the security iss…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:26562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50263</id>
    <title>UBUNTU-CVE-2026-50263</title>
    <updated>2026-10-02T14:55:30.105412+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server-hwe-16.04, Ubuntu:Pro:18.04:LTS: xorg-server, Ubuntu:Pro:18.04:LTS: xorg-server-hwe-18.04, Ubuntu:Pro:20.04:LTS: xorg-server, Ubuntu:22.04:LTS: xorg-server, Ubuntu:22.04:LTS: xwayland, Ubuntu:24.04:LTS: xorg-server, Ubuntu:24.04:LTS: xwayland and 4 more</p>
<p>A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1774</id>
    <title>WID-SEC-W-2026-1774 — X.Org X11 und Xwayland: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:55:30.105451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in X.Org X11 und Xwayland ausnutzen, um Informationen offenzulegen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, und um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1774"/>
  </entry>
</feed>
