Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-34002: Xorg Server allows unauthorized system access
CVE-2026-34002 · published 4 days ago
Summary
A flaw in the Xorg display server software used in several Linux distributions could let an attacker gain full control of the system. The issue has been fixed in newer releases of the affected packages. Install the latest updates for the Xorg packages on your servers to stay protected.
What to do
- Update bellsoft xorg-server to version 21.1.22-r0.
- Update debian xorg-server to version 2:21.1.22-1.
- Update debian xwayland to version 2:24.1.10-1.
- Update debian rootio-xorg-server to version 2:1.20.11-1+deb11u17.root.io.9.
- Update debian xorg-server to version 2:21.1.7-3+deb12u12.
- Update debian xorg-server to version 2:21.1.16-1.3+deb13u2.
- Update xorg-server to version 2:1.20.11-1+deb11u13.aikido.11.
- Update rootio-xorg-server to version 2:1.20.11-1+deb11u13.aikido.11.
- Update xorg-server to version 2:1.20.11-1+deb11u13.aikido.12.
- Update rootio-xorg-server to version 2:1.20.11-1+deb11u13.aikido.12.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:14.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | xorg-server-hwe-16.04 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | xorg-server-hwe-18.04 | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:22.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:22.04:LTS | canonical | xwayland | All versions |
| – | redhat | enterprise_linux |
10.0 6.0 7.0 8.0 9.0 cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
| Echo | echo | xorg-server | All versions |
| Debian:11 | debian | xorg-server | All versions |
| Debian:12 | debian | xorg-server |
< 2:21.1.7-3+deb12u12 Fix: upgrade to 2:21.1.7-3+deb12u12
|
| Debian:13 | debian | xorg-server |
< 2:21.1.16-1.3+deb13u2 Fix: upgrade to 2:21.1.16-1.3+deb13u2
|
| Debian:14 | debian | xorg-server |
< 2:21.1.22-1 Fix: upgrade to 2:21.1.22-1
|
| Debian:12 | debian | xwayland | All versions |
| Debian:13 | debian | xwayland | All versions |
| Debian:14 | debian | xwayland |
< 2:24.1.10-1 Fix: upgrade to 2:24.1.10-1
|
| Alpaquita:stream | bellsoft | xorg-server |
>= 21.1.4-r1, < 21.1.22-r0 Fix: upgrade to 21.1.22-r0
|
| – | x.org | x_server |
All versions
cpe:2.3:a:x.org:x_server:-:*:*:*:*:*:*:* |
| Ubuntu:24.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:24.04:LTS | canonical | xwayland | All versions |
| Ubuntu:25.10 | canonical | xorg-server | All versions |
| Ubuntu:25.10 | canonical | xwayland | All versions |
| Ubuntu:26.04:LTS | canonical | xorg-server | All versions |
| Ubuntu:26.04:LTS | canonical | xwayland | All versions |
| Root:Debian:11 | debian | rootio-xorg-server |
< 2:1.20.11-1+deb11u17.root.io.9 Fix: upgrade to 2:1.20.11-1+deb11u17.root.io.9
|
| Root:Debian:11 | – | xorg-server |
< 2:1.20.11-1+deb11u13.aikido.11 < 2:1.20.11-1+deb11u13.aikido.12 Fix: upgrade to 2:1.20.11-1+deb11u13.aikido.11
|
| Root:Debian:11 | – | rootio-xorg-server |
< 2:1.20.11-1+deb11u13.aikido.11 < 2:1.20.11-1+deb11u13.aikido.12 Fix: upgrade to 2:1.20.11-1+deb11u13.aikido.11
|
Original advisory text
CVE-2026-34002 in xorg-server - Patched by Root
Root has patched CVE-2026-34002 in the xorg-server package for Root:Debian:11. Multiple fixed versions available.
References
- https://security-tracker.debian.org/tracker/CVE-2026-34002 Vendor Advisory
- https://advisory.echohq.com/cve/CVE-2026-34002 URL
- https://docs.bell-sw.com/security/cves/CVE-2026-34002 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-34002 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-34002 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-34002 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:20547
- https://access.redhat.com/errata/RHSA-2026:20555
- https://access.redhat.com/errata/RHSA-2026:20557
- https://access.redhat.com/errata/RHSA-2026:20558
- https://access.redhat.com/errata/RHSA-2026:20560
- https://access.redhat.com/errata/RHSA-2026:20561
- https://access.redhat.com/errata/RHSA-2026:20562
- https://access.redhat.com/errata/RHSA-2026:20563
- https://access.redhat.com/errata/RHSA-2026:20575
- https://access.redhat.com/errata/RHSA-2026:20576
- https://access.redhat.com/errata/RHSA-2026:20590
- https://access.redhat.com/errata/RHSA-2026:21699
- https://access.redhat.com/errata/RHSA-2026:21712
- https://access.redhat.com/errata/RHSA-2026:21715
- https://access.redhat.com/errata/RHSA-2026:21716
- https://access.redhat.com/errata/RHSA-2026:21718
- https://access.redhat.com/errata/RHSA-2026:21741
- https://access.redhat.com/errata/RHSA-2026:21742
- https://access.redhat.com/errata/RHSA-2026:22424
- https://access.redhat.com/errata/RHSA-2026:22456
- https://access.redhat.com/errata/RHSA-2026:23254
- https://access.redhat.com/errata/RHSA-2026:23255
- https://access.redhat.com/errata/RHSA-2026:23496
- https://access.redhat.com/errata/RHSA-2026:24341
- https://bugzilla.redhat.com/show_bug.cgi?id=2451112 Issue Tracking Third Party Advisory
- https://lists.x.org/archives/xorg-announce/2026-April/003677.html Third Party Advisory
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker partial control
Type
CWE-805Buffer Access with Incorrect Length Value
Timeline
Published6 Oct 2026
Updated7 Oct 2026
First seen14 Apr 2026
Sources
CVE-2026-34002 · NVD
BELL-CVE-2026-34002 · OSV
DEBIAN-CVE-2026-34002 · OSV
UBUNTU-CVE-2026-34002 · OSV
ECHO-43b7-d1f3-e5f3 · OSV
Track software like this
Free during beta