[CLSA-2025:1763647564] xorg-x11-server-Xwayland: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2025-11-20 14:06:08 UTC
Description:
- CVE-2024-0409: fix incorrect cursor private key usage in Xwayland/Xephyr that caused XSELINUX devPrivates corruption - CVE-2025-26597: fix buffer overflow in XkbChangeTypesOfKey() by properly resizing key syms and actions when nGroups is zero - CVE-2025-26594: fix root cursor lifetime handling to prevent use-after-free and stale references
Updated packages:
  • xorg-x11-server-Xwayland-21.1.3-7.el9.tuxcare.els7.i686.rpm
    sha:5c9e9ddc154f7a147369e81911b709912f746fdbe458cf3d31c2df4893500c81
  • xorg-x11-server-Xwayland-21.1.3-7.el9.tuxcare.els7.x86_64.rpm
    sha:528bb72730a5f3f60ee73ffdc85e63e186f3e2af45db24f753d7446e3d20657d
  • xorg-x11-server-Xwayland-devel-21.1.3-7.el9.tuxcare.els7.i686.rpm
    sha:560d308270e2b4aa055c421f8fe9f74c7fe52f35ce626dc1e82e32501d72d8fc
  • xorg-x11-server-Xwayland-devel-21.1.3-7.el9.tuxcare.els7.x86_64.rpm
    sha:6d1110df5e2e70fdaa5f7d25d1281a68e6649545df4ddfe3b4cf956576138755
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.