Hi,
The following vulnerabilities were published for xwayland.
CVE-2026-88812[0]:
| XKB SetGeometry TextDoodad Double Free
CVE-2026-93515[1]:
| Present Extension Cross-Window Notify Use-After-Free
CVE-2026-93516[2]:
| XInput Passive Grab modifierDevice Use-After-Free
CVE-2026-93517[3]:
| GLX RenderLarge Heap Buffer Overflow
CVE-2026-93518[4]:
| XKB ResizeKeyType Numeric Truncation
CVE-2026-93519[5]:
| XFixes Pointer Barrier Event List Buffer Overflow
CVE-2026-93520[6]:
| XKB ChangeKeycodeRange Heap Out-of-Bounds Write
CVE-2026-93521[7]:
| RandR ChangeProviderProperty Heap Buffer Overflow
CVE-2026-93522[8]:
| Glamor CopyArea CPU-FBO Heap Buffer Overflow
CVE-2026-93523[9]:
| XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write
CVE-2026-93524[10]:
| XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read
CVE-2026-93536[11]:
| GestureBuildSprite Use-After-Free
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-88812
https://www.cve.org/CVERecord?id=CVE-2026-88812
[1] https://security-tracker.debian.org/tracker/CVE-2026-93515
https://www.cve.org/CVERecord?id=CVE-2026-93515
[2] https://security-tracker.debian.org/tracker/CVE-2026-93516
https://www.cve.org/CVERecord?id=CVE-2026-93516
[3] https://security-tracker.debian.org/tracker/CVE-2026-93517
https://www.cve.org/CVERecord?id=CVE-2026-93517
[4] https://security-tracker.debian.org/tracker/CVE-2026-93518
https://www.cve.org/CVERecord?id=CVE-2026-93518
[5] https://security-tracker.debian.org/tracker/CVE-2026-93519
https://www.cve.org/CVERecord?id=CVE-2026-93519
[6] https://security-tracker.debian.org/tracker/CVE-2026-93520
https://www.cve.org/CVERecord?id=CVE-2026-93520
[7] https://security-tracker.debian.org/tracker/CVE-2026-93521
https://www.cve.org/CVERecord?id=CVE-2026-93521
[8] https://security-tracker.debian.org/tracker/CVE-2026-93522
https://www.cve.org/CVERecord?id=CVE-2026-93522
[9] https://security-tracker.debian.org/tracker/CVE-2026-93523
https://www.cve.org/CVERecord?id=CVE-2026-93523
[10] https://security-tracker.debian.org/tracker/CVE-2026-93524
https://www.cve.org/CVERecord?id=CVE-2026-93524
[11] https://security-tracker.debian.org/tracker/CVE-2026-93536
https://www.cve.org/CVERecord?id=CVE-2026-93536
[12] https://lists.x.org/archives/xorg-announce/2026-October/003747.html
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore