VOOZH about

URL: https://www.phoronix.com/news/XWayland-24.1.8-X.Org-21.1.8

⇱ XWayland 24.1.8 & X.Org Server 21.1.18 Further Address Yesterday's Security Disclosures - Phoronix


👁 Phoronix

XWayland 24.1.8 & X.Org Server 21.1.18 Further Address Yesterday's Security Disclosures

Written by Michael Larabel in X.Org on 18 June 2025 at 01:03 PM EDT. 35 Comments
Released yesterday were X.Org Server 21.1.17 and XWayland 24.1.7 to address another batch of six security vulnerabilities reported by security researchers. Out today is X.Org Server 21.1.18 and XWayland 24.1.8 in order to further button up one of the security issues reported yesterday.

Today's XWayland and X.Org Server point releases are for adding an integer overflow check on the BigRequest length as part of addressing CVE-2025-49176, which is around possible integer overflows within the Big Requests Extension. A simple if statement is added to the C code to further fend off possible integer overflow conditions.

👁 XWayland 24.1.8


So for those interested you can now grab xorg-server 21.1.18 and xwayland 24.1.8.

As the ERNW security researchers who discovered this latest batch of X.Org Server flaws wrote yesterday:
"The X.Org X server is a aged and large project that grew over time with the help of the open-source community. All of these issues gave me a feeling that the source code itself can best describe: party_like_its_1989 = TRUE;"

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.