Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-34000: xorg-server could let attackers run code

CVE-2026-34000 · published 4 days ago
Summary

The Xorg display server used in several Linux distributions, including Red Hat Enterprise Linux, Debian, and others, has a security weakness that could allow a malicious user to execute code on the system. This could give an attacker control over the affected machines. Install the latest updated versions of the Xorg packages from your vendor to protect your systems.

What to do
  • Update bellsoft xorg-server to version 21.1.22-r0.
  • Update debian xorg-server to version 2:21.1.22-1.
  • Update debian xwayland to version 2:24.1.10-1.
  • Update debian rootio-xorg-server to version 2:1.20.11-1+deb11u17.root.io.9.
  • Update debian xorg-server to version 2:21.1.7-3+deb12u12.
  • Update debian xorg-server to version 2:21.1.16-1.3+deb13u2.
  • Update xorg-server to version 2:1.20.11-1+deb11u13.aikido.11.
  • Update rootio-xorg-server to version 2:1.20.11-1+deb11u13.aikido.11.
  • Update xorg-server to version 2:1.20.11-1+deb11u13.aikido.12.
  • Update rootio-xorg-server to version 2:1.20.11-1+deb11u13.aikido.12.
Affected software
Ecosystem VendorProductAffected versions
– redhat enterprise_linux 7.0
8.0
9.0
10.0
6.0
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Debian:11 debian xorg-server All versions
Debian:12 debian xorg-server < 2:21.1.7-3+deb12u12
Fix: upgrade to 2:21.1.7-3+deb12u12
Debian:13 debian xorg-server < 2:21.1.16-1.3+deb13u2
Fix: upgrade to 2:21.1.16-1.3+deb13u2
Debian:14 debian xorg-server < 2:21.1.22-1
Fix: upgrade to 2:21.1.22-1
Debian:12 debian xwayland All versions
Debian:13 debian xwayland All versions
Debian:14 debian xwayland < 2:24.1.10-1
Fix: upgrade to 2:24.1.10-1
Echo echo xorg-server All versions
Alpaquita:stream bellsoft xorg-server >= 21.1.4-r1, < 21.1.22-r0
Fix: upgrade to 21.1.22-r0
– x.org x_server All versions
cpe:2.3:a:x.org:x_server:-:*:*:*:*:*:*:*
Ubuntu:Pro:14.04:LTS canonical xorg-server All versions
Ubuntu:Pro:16.04:LTS canonical xorg-server All versions
Ubuntu:Pro:16.04:LTS canonical xorg-server-hwe-16.04 All versions
Ubuntu:Pro:18.04:LTS canonical xorg-server All versions
Ubuntu:Pro:18.04:LTS canonical xorg-server-hwe-18.04 All versions
Ubuntu:Pro:20.04:LTS canonical xorg-server All versions
Ubuntu:22.04:LTS canonical xorg-server All versions
Ubuntu:22.04:LTS canonical xwayland All versions
Ubuntu:24.04:LTS canonical xorg-server All versions
Ubuntu:24.04:LTS canonical xwayland All versions
Ubuntu:25.10 canonical xorg-server All versions
Ubuntu:25.10 canonical xwayland All versions
Ubuntu:26.04:LTS canonical xorg-server All versions
Ubuntu:26.04:LTS canonical xwayland All versions
Root:Debian:11 debian rootio-xorg-server < 2:1.20.11-1+deb11u17.root.io.9
Fix: upgrade to 2:1.20.11-1+deb11u17.root.io.9
Root:Debian:11 – xorg-server < 2:1.20.11-1+deb11u13.aikido.11
< 2:1.20.11-1+deb11u13.aikido.12
Fix: upgrade to 2:1.20.11-1+deb11u13.aikido.11
Root:Debian:11 – rootio-xorg-server < 2:1.20.11-1+deb11u13.aikido.11
< 2:1.20.11-1+deb11u13.aikido.12
Fix: upgrade to 2:1.20.11-1+deb11u13.aikido.11
Original advisory text
CVE-2026-34000 in xorg-server - Patched by Root
Root has patched CVE-2026-34000 in the xorg-server package for Root:Debian:11. Multiple fixed versions available.
References
Fix within
Internet-facing 60 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-125Out-of-bounds Read
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen14 Apr 2026
Track software like this
Free during beta