Updated x11-server, x11-server-xwayland & tigervnc packages fix security vulnerabilities
Publication date: 26 May 2026Modification date: 26 May 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-33999 , CVE-2026-34000 , CVE-2026-34001 , CVE-2026-34002 , CVE-2026-34003
Description
XKB Integer Underflow in XkbSetCompatMap(). (CVE-2026-33999)
XKB Out-of-bounds Read in CheckSetGeom(). (CVE-2026-34000)
XSYNC Use-after-free in miSyncTriggerFence(). (CVE-2026-34001)
XKB Out-of-bounds read in CheckModifierMap(). (CVE-2026-34002)
XKB Buffer overflow in CheckKeyTypes(). (CVE-2026-34003)
References
- https://bugs.mageia.org/show_bug.cgi?id=35366
- https://www.openwall.com/lists/oss-security/2026/04/14/8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JGQLR43Z7T6IISLCOC2Q4WB3D4YWB4QS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RULWKTYNOMHH3NTJ36SDNJVWKXYJ4VVO/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33999
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34000
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34001
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34002
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34003
SRPMS
9/core
- x11-server-21.1.8-7.10.mga9
- x11-server-xwayland-22.1.9-1.10.mga9
- tigervnc-1.13.1-2.11.mga9