Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-34002: Xorg Server allows unauthorized system access

CVE-2026-34002 · published 4 days ago
Summary

A flaw in the Xorg display server software used in several Linux distributions could let an attacker gain full control of the system. The issue has been fixed in newer releases of the affected packages. Install the latest updates for the Xorg packages on your servers to stay protected.

What to do
  • Update bellsoft xorg-server to version 21.1.22-r0.
  • Update debian xorg-server to version 2:21.1.22-1.
  • Update debian xwayland to version 2:24.1.10-1.
  • Update debian rootio-xorg-server to version 2:1.20.11-1+deb11u17.root.io.9.
  • Update debian xorg-server to version 2:21.1.7-3+deb12u12.
  • Update debian xorg-server to version 2:21.1.16-1.3+deb13u2.
  • Update xorg-server to version 2:1.20.11-1+deb11u13.aikido.11.
  • Update rootio-xorg-server to version 2:1.20.11-1+deb11u13.aikido.11.
  • Update xorg-server to version 2:1.20.11-1+deb11u13.aikido.12.
  • Update rootio-xorg-server to version 2:1.20.11-1+deb11u13.aikido.12.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:14.04:LTS canonical xorg-server All versions
Ubuntu:Pro:16.04:LTS canonical xorg-server All versions
Ubuntu:Pro:16.04:LTS canonical xorg-server-hwe-16.04 All versions
Ubuntu:Pro:18.04:LTS canonical xorg-server All versions
Ubuntu:Pro:18.04:LTS canonical xorg-server-hwe-18.04 All versions
Ubuntu:Pro:20.04:LTS canonical xorg-server All versions
Ubuntu:22.04:LTS canonical xorg-server All versions
Ubuntu:22.04:LTS canonical xwayland All versions
– redhat enterprise_linux 10.0
6.0
7.0
8.0
9.0
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Echo echo xorg-server All versions
Debian:11 debian xorg-server All versions
Debian:12 debian xorg-server < 2:21.1.7-3+deb12u12
Fix: upgrade to 2:21.1.7-3+deb12u12
Debian:13 debian xorg-server < 2:21.1.16-1.3+deb13u2
Fix: upgrade to 2:21.1.16-1.3+deb13u2
Debian:14 debian xorg-server < 2:21.1.22-1
Fix: upgrade to 2:21.1.22-1
Debian:12 debian xwayland All versions
Debian:13 debian xwayland All versions
Debian:14 debian xwayland < 2:24.1.10-1
Fix: upgrade to 2:24.1.10-1
Alpaquita:stream bellsoft xorg-server >= 21.1.4-r1, < 21.1.22-r0
Fix: upgrade to 21.1.22-r0
– x.org x_server All versions
cpe:2.3:a:x.org:x_server:-:*:*:*:*:*:*:*
Ubuntu:24.04:LTS canonical xorg-server All versions
Ubuntu:24.04:LTS canonical xwayland All versions
Ubuntu:25.10 canonical xorg-server All versions
Ubuntu:25.10 canonical xwayland All versions
Ubuntu:26.04:LTS canonical xorg-server All versions
Ubuntu:26.04:LTS canonical xwayland All versions
Root:Debian:11 debian rootio-xorg-server < 2:1.20.11-1+deb11u17.root.io.9
Fix: upgrade to 2:1.20.11-1+deb11u17.root.io.9
Root:Debian:11 – xorg-server < 2:1.20.11-1+deb11u13.aikido.11
< 2:1.20.11-1+deb11u13.aikido.12
Fix: upgrade to 2:1.20.11-1+deb11u13.aikido.11
Root:Debian:11 – rootio-xorg-server < 2:1.20.11-1+deb11u13.aikido.11
< 2:1.20.11-1+deb11u13.aikido.12
Fix: upgrade to 2:1.20.11-1+deb11u13.aikido.11
Original advisory text
CVE-2026-34002 in xorg-server - Patched by Root
Root has patched CVE-2026-34002 in the xorg-server package for Root:Debian:11. Multiple fixed versions available.
References
Fix within
Internet-facing 60 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-805Buffer Access with Incorrect Length Value
Timeline
Published6 Oct 2026
Updated7 Oct 2026
First seen14 Apr 2026
Track software like this
Free during beta