Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-34000: xorg-server could let attackers run code
CVE-2026-34000 · published 4 days ago
Summary
The Xorg display server used in several Linux distributions, including Red Hat Enterprise Linux, Debian, and others, has a security weakness that could allow a malicious user to execute code on the system. This could give an attacker control over the affected machines. Install the latest updated versions of the Xorg packages from your vendor to protect your systems.
What to do
- Update bellsoft xorg-server to version 21.1.22-r0.
- Update debian xorg-server to version 2:21.1.22-1.
- Update debian xwayland to version 2:24.1.10-1.
- Update debian rootio-xorg-server to version 2:1.20.11-1+deb11u17.root.io.9.
- Update debian xorg-server to version 2:21.1.7-3+deb12u12.
- Update debian xorg-server to version 2:21.1.16-1.3+deb13u2.
- Update xorg-server to version 2:1.20.11-1+deb11u13.aikido.11.
- Update rootio-xorg-server to version 2:1.20.11-1+deb11u13.aikido.11.
- Update xorg-server to version 2:1.20.11-1+deb11u13.aikido.12.
- Update rootio-xorg-server to version 2:1.20.11-1+deb11u13.aikido.12.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | redhat | enterprise_linux |
7.0 8.0 9.0 10.0 6.0 cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* |
| Debian:11 | debian | xorg-server | All versions |
| Debian:12 | debian | xorg-server |
< 2:21.1.7-3+deb12u12 Fix: upgrade to 2:21.1.7-3+deb12u12
|
| Debian:13 | debian | xorg-server |
< 2:21.1.16-1.3+deb13u2 Fix: upgrade to 2:21.1.16-1.3+deb13u2
|
| Debian:14 | debian | xorg-server |
< 2:21.1.22-1 Fix: upgrade to 2:21.1.22-1
|
| Debian:12 | debian | xwayland | All versions |
| Debian:13 | debian | xwayland | All versions |
| Debian:14 | debian | xwayland |
< 2:24.1.10-1 Fix: upgrade to 2:24.1.10-1
|
| Echo | echo | xorg-server | All versions |
| Alpaquita:stream | bellsoft | xorg-server |
>= 21.1.4-r1, < 21.1.22-r0 Fix: upgrade to 21.1.22-r0
|
| – | x.org | x_server |
All versions
cpe:2.3:a:x.org:x_server:-:*:*:*:*:*:*:* |
| Ubuntu:Pro:14.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | xorg-server-hwe-16.04 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | xorg-server-hwe-18.04 | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:22.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:22.04:LTS | canonical | xwayland | All versions |
| Ubuntu:24.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:24.04:LTS | canonical | xwayland | All versions |
| Ubuntu:25.10 | canonical | xorg-server | All versions |
| Ubuntu:25.10 | canonical | xwayland | All versions |
| Ubuntu:26.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:26.04:LTS | canonical | xwayland | All versions |
| Root:Debian:11 | debian | rootio-xorg-server |
< 2:1.20.11-1+deb11u17.root.io.9 Fix: upgrade to 2:1.20.11-1+deb11u17.root.io.9
|
| Root:Debian:11 | – | xorg-server |
< 2:1.20.11-1+deb11u13.aikido.11 < 2:1.20.11-1+deb11u13.aikido.12 Fix: upgrade to 2:1.20.11-1+deb11u13.aikido.11
|
| Root:Debian:11 | – | rootio-xorg-server |
< 2:1.20.11-1+deb11u13.aikido.11 < 2:1.20.11-1+deb11u13.aikido.12 Fix: upgrade to 2:1.20.11-1+deb11u13.aikido.11
|
Original advisory text
CVE-2026-34000 in xorg-server - Patched by Root
Root has patched CVE-2026-34000 in the xorg-server package for Root:Debian:11. Multiple fixed versions available.
References
- https://security-tracker.debian.org/tracker/CVE-2026-34000 Vendor Advisory
- https://advisory.echohq.com/cve/CVE-2026-34000 URL
- https://docs.bell-sw.com/security/cves/CVE-2026-34000 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2451107 Issue Tracking Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-34000 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-34000 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-34000 Third Party Advisory
- https://lists.x.org/archives/xorg-announce/2026-April/003677.html Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:19342
- https://access.redhat.com/errata/RHSA-2026:20547
- https://access.redhat.com/errata/RHSA-2026:20555
- https://access.redhat.com/errata/RHSA-2026:20557
- https://access.redhat.com/errata/RHSA-2026:20558
- https://access.redhat.com/errata/RHSA-2026:20560
- https://access.redhat.com/errata/RHSA-2026:20561
- https://access.redhat.com/errata/RHSA-2026:20562
- https://access.redhat.com/errata/RHSA-2026:20563
- https://access.redhat.com/errata/RHSA-2026:20575
- https://access.redhat.com/errata/RHSA-2026:20576
- https://access.redhat.com/errata/RHSA-2026:20590
- https://access.redhat.com/errata/RHSA-2026:21699
- https://access.redhat.com/errata/RHSA-2026:21712
- https://access.redhat.com/errata/RHSA-2026:21715
- https://access.redhat.com/errata/RHSA-2026:21716
- https://access.redhat.com/errata/RHSA-2026:21718
- https://access.redhat.com/errata/RHSA-2026:21741
- https://access.redhat.com/errata/RHSA-2026:21742
- https://access.redhat.com/errata/RHSA-2026:22424
- https://access.redhat.com/errata/RHSA-2026:22456
- https://access.redhat.com/errata/RHSA-2026:23254
- https://access.redhat.com/errata/RHSA-2026:23255
- https://access.redhat.com/errata/RHSA-2026:23496
- https://access.redhat.com/errata/RHSA-2026:24341
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker partial control
Severity
9.1
Critical
Type
CWE-125Out-of-bounds Read
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen14 Apr 2026
Sources
BELL-CVE-2026-34000 · OSV
DEBIAN-CVE-2026-34000 · OSV
UBUNTU-CVE-2026-34000 · OSV
CVE-2026-34000 · NVD
ECHO-3dd8-08d4-1c16 · OSV
Track software like this
Free during beta