#1141703 xorg-server: CVE-2026-55999 CVE-2026-56000

Package:
src:xorg-server
Source:
src:xorg-server
Submitter:
Salvatore Bonaccorso
Date:
2026-09-12 16:19:02 UTC
Severity:
normal
Tags:
#1141703#5
Date:
2026-07-09 03:50:52 UTC
From:
To:
Hi,

The following vulnerabilities were published for xorg-server.

CVE-2026-55999[0]:
| Local attackers with a X connection able to provide PCX fonts to the
| X  server xorg-server before 21.2.24 and xwayland before 24.1.13
| could  cause a heap buffer overflow via SetFont due to missing glyph
| boundary checks.


CVE-2026-56000[1]:
| Local attackers with a X connection able to provide GLX commit to
| the X server xorg-server before 21.2.24 and xwayland before 24.1.13
| could cause a Heap Use After Free, due to CommonMakeCurrent()
| pointing into potentially reallocated memory.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55999
https://www.cve.org/CVERecord?id=CVE-2026-55999
[1] https://security-tracker.debian.org/tracker/CVE-2026-56000
https://www.cve.org/CVERecord?id=CVE-2026-56000
[2] https://www.openwall.com/lists/oss-security/2026/07/08/2

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1141703#12
Date:
2026-08-05 10:36:32 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
xorg-server, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141703@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emilio Pozuelo Monfort <pochu@debian.org> (supplier of updated xorg-server package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 05 Aug 2026 12:04:38 +0200
Source: xorg-server
Architecture: source
Version: 2:21.1.24-1
Distribution: unstable
Urgency: medium
Maintainer: Debian X Strike Force <debian-x@lists.debian.org>
Changed-By: Emilio Pozuelo Monfort <pochu@debian.org>
Closes: 1141703
Changes:
 xorg-server (2:21.1.24-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release.
     -  CVE-2026-55999: glamor Font Atlas Heap Buffer Overflow
     -  CVE-2026-56000: GLX contextTags Use-After-Free in CommonMakeCurrent()
     Closes: #1141703.
Checksums-Sha1:
 4d1bcd1a04a34ad9a14b7001a193c929eb91cf84 4040 xorg-server_21.1.24-1.dsc
 2301d8084a777b942f3d7e3860a506c855986996 9036382 xorg-server_21.1.24.orig.tar.gz
 8130aaa668b7e2d49859c0b27201b5d3cb59dbb9 178470 xorg-server_21.1.24-1.diff.gz
 3deb538ad45c7289b8e6af0da106c797460265e9 9435 xorg-server_21.1.24-1_source.buildinfo
Checksums-Sha256:
 03e384de62bdbe4a5830e19f73fa0fdda97f7071f1cdd56ea18e2335613aa0f6 4040 xorg-server_21.1.24-1.dsc
 d01ccd7ba48ec9d6815aeef5fb408d0c307ab6be21d20ff0b54b11f1c2b8a075 9036382 xorg-server_21.1.24.orig.tar.gz
 d0c8e5abf7ca569d08b2ecde7f45e4178d28b415113844ce5a0395c10ac6e91a 178470 xorg-server_21.1.24-1.diff.gz
 b25510af9b80653a1579c67d1be3944c0592b4353495f6b94005503e1a2ec119 9435 xorg-server_21.1.24-1_source.buildinfo
Files:
 20a7f5bfc808bfbb7cec06996a0d0e50 4040 x11 optional xorg-server_21.1.24-1.dsc
 f6e5b3ae9013a4b926a31d11c5656202 9036382 x11 optional xorg-server_21.1.24.orig.tar.gz
 e12e06170600d4e704f61ebc2771c1df 178470 x11 optional xorg-server_21.1.24-1.diff.gz
 9a20e6a2ed9444e598f9a4f49aa8f8c8 9435 x11 optional xorg-server_21.1.24-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmpzCxEACgkQnUbEiOQ2
gwJBYxAAg4Hs2xJW97KyEZFZJvMHm94XzEGuXcu2wmTLRRfNhSkbLpymp6JzvhKJ
721w6/y8K0BNguB4fdxlfe4SNItooho/4SF7BVqlD4wAMpSQDtB7haNh6m0RrvOO
AwM34zG++V3GeUhaaaDYhgieMSSeayYbJW33DnYr32+TeNWmkHVCTabOhsE5PWlW
si1HOrUqT+1O4CezOts+FdawyVlWtSUcYAMHoPk3MBCbud5OaPngAmLFL+p7zzvK
9uCUXiuhSuBK6in02ND9Y2SyN8mNw+HWco+bOtp26VdGf9ks4u1EJVNhrcrmZzKC
u5TEBssTK+PUf1S3bCLiOBgZHwdGDAq9e5AMIoVeIp/wj8m3SOLxmbsXRReiDhsW
LQRiRy5oNPAjCGhJU7qGLRSu01pRZX2at5NyK4iPl72TnQEGQOl1ZZqe+Y/AaqBr
B3f9FjZEPtZpTaDSerhnXWU+Oz77N5+FQeUitYjAXHx7eQzArLId62Pl4MtFkOo1
ZzGjfAyOaG4JDuk4Io6uDnndDwjjzN9MJDJzT02AJBtN5BGItWaPiss0nHqoIYcx
nUmi9+9ZTSKkmxd5CNqtq2EE69bdd7kbGYuLQSBDejYKurkDfTdABjKMXTaFaNnT
PLh1rKNKHNCzKyidLdxHUf1gh3QtsGlAGdLYx2eOnOtwc2PvYXk=
=wwW2
-----END PGP SIGNATURE-----

#1141703#17
Date:
2026-09-12 16:17:19 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
xorg-server, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141703@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated xorg-server package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 05 Sep 2026 07:52:43 +0200
Source: xorg-server
Architecture: source
Version: 2:21.1.16-1.3+deb13u4
Distribution: trixie-security
Urgency: high
Maintainer: Debian X Strike Force <debian-x@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1141703
Changes:
 xorg-server (2:21.1.16-1.3+deb13u4) trixie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * GLX: Free the tag of the old context later
   * glx: free old context tag before allocating new one in CommonMakeCurrent
     (CVE-2026-56000) (Closes: #1141703)
   * fb/mi/glamor: reject glyphs with negative dimensions
   * glamor: reject fonts with per-glyph metrics exceeding maxbounds
     (CVE-2026-55999) (Closes: #1141703)
Checksums-Sha1:
 edd9fddd33e8c53a0b2f0b0fade80c08bff5de17 4236 xorg-server_21.1.16-1.3+deb13u4.dsc
 fbfa24786a62f8aad0213e30d27e80d2aa2d1aaa 207997 xorg-server_21.1.16-1.3+deb13u4.diff.gz
 8e48bb18c29683ab6c3c3fd6f3dc5e6feeaf0e3e 8515 xorg-server_21.1.16-1.3+deb13u4_source.buildinfo
Checksums-Sha256:
 ef0e04fe6c415f94d8a90b5305974427825865e76ed61154005565be8602a2ef 4236 xorg-server_21.1.16-1.3+deb13u4.dsc
 ad8b35823a0b82323ecdb3b3a6896d652106ed89ec927e49016c9eaefa35bf6b 207997 xorg-server_21.1.16-1.3+deb13u4.diff.gz
 40b3d26325aacd5e506e362b72fe46f55240080bbfc9b9cdf208e1e780798946 8515 xorg-server_21.1.16-1.3+deb13u4_source.buildinfo
Files:
 f47fc24e388514ca9b1ceff132210912 4236 x11 optional xorg-server_21.1.16-1.3+deb13u4.dsc
 33516ef2358203f46a646cef6b7de250 207997 x11 optional xorg-server_21.1.16-1.3+deb13u4.diff.gz
 03321089318456920fbb06602e4283bf 8515 x11 optional xorg-server_21.1.16-1.3+deb13u4_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqfBvBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E2CIP+QEXtwDNr1zZjJvXL906nsbZ0DzkjW4Z
PItFGYMdj1Wf5BvjNzwt+dwu+anPj0AdHFD5/hJOcblqZoWK5I2IoN1cptJE5it1
muLnCy/IOHAMUIj69crdyRizeLwYXDrCnCQ4rCuJAQg5d/rjozcD4hF3c0nDw3AN
RLEFuAV/ik/4yfCeXNfA0Gf2WpOi4+ARj258VL7sFFmbRYGAKhIq8w4cLVMefeeP
GdatHzwA9Du9blBxB1+SCbOPDCGcCr5hGwzK+XicVA4Raa1EYGB20pihM3KmXgr5
saiLnRAkGX+O1Og2z+67i3kl8CmSv1BRK35QBluyOfLwwqjKUeLcb1oHfV4z8H6a
y2Fv2jz9Wbb9y8VDgKk0xSTia8VeOAtd4TnGaT5U/ASciCAFokM9KbbiBpQT55sh
1yhu6HT9p2eQ7RME3Ea6s835hvMsOENZb3zsxHSb7S4tfGzbdbXRzmjVJHHI2pg0
EFCDrBSnNKO5Xa4jqgBqawGW/LVAQRrpn/2QUBSjMuvqrKefOglQFviufVFd/4rJ
rpoqx6t73W9f6VEAkSch7sOknDFMetCaRO1dNqKDzs7iWvuqbeEAUrO58UYrVwS7
oXOb6WVJP0XJDxNStShHw6c4IdcZu7txvdduO19CG3nOrgVhEh3epEGdHp9CtCd7
Muq9+8WxA4H1
=IQtr
-----END PGP SIGNATURE-----