X.Org and Xwayland: Security vulnerabilities enable code smuggling
Several security vulnerabilities in X.Org and Xwayland allow attackers to smuggle in malicious code. Some updates are available.

(Image: Erstellt mit KI in Bing Designer durch heise online / dmk)
Several security vulnerabilities have been discovered in the X.org X11 server and Xwayland. They may allow attackers to inject and execute malicious code. The major Linux distributions are already distributing updated packages.
The discoverer of the gaps, Jan-Niklas Sohn, has reported the eight vulnerabilities according to Ubuntu. In summary, the Ubuntu maintainers write that the X.org X server did not handle certain memory operations correctly: “Attackers can use these issues to crash the X server, resulting in a denial of service, or possibly execute arbitrary code.” However, the authors of the security memo do not discuss how such attacks could look and be detected.
Updated X.org and Xwayland packages
Ubuntu is already distributing updated packages for Ubuntu 20.04, 22.04, 24.04 and 24.10. After installing the updates, those affected should restart their systems to make the necessary changes. Redhat also has updates in its program. At the time of reporting, SUSE still appears to be working on updated packages, and the Debian “Security-Announce” mailing list does not yet contain any information on updates in February. However, these should be released shortly. Admins should apply them as soon as they are available, provided that the X.Org server and Xwayland are still installed on the systems for compatibility reasons, for example.
The vulnerabilities in detail:
- A use-after-free flaw was found in X.Org and Xwayland CVE-2025-26594, CVSS 7.8, risk “high”
- A buffer overflow flaw was found in X.Org and Xwayland CVE-2025-26595, CVSS 7.8, high
- A heap overflow flaw was found in X.Org and Xwayland CVE-2025-26596, CVSS 7.8, high
- A buffer overflow flaw was found in X.Org and Xwayland CVE-2025-26597, CVSS 7.8, high
- An out-of-bounds write flaw was found in X.Org and Xwayland CVE-2025-26598, CVSS 7.8, high
- An access to an uninitialized pointer flaw was found in X.Org and Xwayland CVE-2025-26599, CVSS 7.8, high
- A use-after-free flaw was found in X.Org and Xwayland CVE-2025-26600, CVSS 7.8, high
- A use-after-free flaw was found in X.Org and Xwayland CVE-2025-26601, CVSS 7.8, high
Read also
X11-Nachfolger: Wo ist Wayland?
(dmk)