Published October 7, 2026 · Added October 7, 2026

Another Dozen Vulnerabilities Found In The X.Org Server & XWayland

Phoronix reports that TrendAI's Zero Day Initiative disclosed twelve more security vulnerabilities in the X.Org Server codebase and XWayland, found with the assistance of AI, extending a long run of disclosures against the display server that a researcher described more than a decade ago as being in even worse shape than it looks. The flaws, present in versions before xorg-server-21.1.25 and xwayland-24.1.14, are mostly use-after-free, heap buffer overflow, out-of-bounds read and write, double free and numeric truncation bugs, spanning XKB, Present, XInput, GLX, XFixes, RandR, Glamor and gesture code.

Phoronix reports that TrendAI’s Zero Day Initiative disclosed twelve more security vulnerabilities in the X.Org Server codebase and XWayland, found with the assistance of AI, extending a long run of disclosures against the display server that a researcher described more than a decade ago as being in even worse shape than it looks. The flaws, present in versions before xorg-server-21.1.25 and xwayland-24.1.14, are mostly use-after-free, heap buffer overflow, out-of-bounds read and write, double free and numeric truncation bugs, spanning XKB, Present, XInput, GLX, XFixes, RandR, Glamor and gesture code.

Read the original story.

Source: Phoronix