[Git][security-tracker-team/security-tracker][master] Reserve DLA-4738-1 for xorg-server

Arnaud Rebillout (@arnaudr) arnaudr at debian.org
Thu Aug 13 05:43:53 BST 2026



Arnaud Rebillout pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e004f744 by Arnaud Rebillout at 2026-08-13T11:43:34+07:00
Reserve DLA-4738-1 for xorg-server

- - - - -


2 changed files:

- data/CVE/list
- data/DLA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -92690,7 +92690,6 @@ CVE-2026-34003 (A flaw was found in the X.Org X server's XKB key types request v
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
-	[bullseye] - xorg-server <postponed> (Minor issue)
 	- xwayland 2:24.1.10-1
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
 	[bookworm] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -92701,7 +92700,6 @@ CVE-2026-34002 (A flaw was found in the X.Org X server. This vulnerability, an o
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
-	[bullseye] - xorg-server <postponed> (Minor issue)
 	- xwayland 2:24.1.10-1
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
 	[bookworm] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -92711,7 +92709,6 @@ CVE-2026-34001 (A flaw was found in the X.Org X server. This use-after-free vuln
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
-	[bullseye] - xorg-server <postponed> (Minor issue)
 	- xwayland 2:24.1.10-1
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
 	[bookworm] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -92721,7 +92718,6 @@ CVE-2026-34000 (A flaw was found in the X.Org X server. This out-of-bounds read
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
-	[bullseye] - xorg-server <postponed> (Minor issue)
 	- xwayland 2:24.1.10-1
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
 	[bookworm] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -92731,7 +92727,6 @@ CVE-2026-33999 (A flaw was found in the X.Org X server. This integer underflow v
 	- xorg-server 2:21.1.22-1
 	[trixie] - xorg-server 2:21.1.16-1.3+deb13u2
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u12
-	[bullseye] - xorg-server <postponed> (Minor issue)
 	- xwayland 2:24.1.10-1
 	[trixie] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
 	[bookworm] - xwayland <ignored> (Minor issue; Xwayland shouldn't be running as root)
@@ -241353,7 +241348,6 @@ CVE-2024-13126 (The Download Manager WordPress plugin before 3.3.07 doesn't prev
 	NOT-FOR-US: WordPress plugin
 CVE-2022-49737 (In X.Org X server 20.11 through 21.1.16, when a client application use ...)
 	- xorg-server 2:21.1.16-1.1 (bug #1081338)
-	[bullseye] - xorg-server <postponed> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1260
 	NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/commit/dc7cb45482cea6ccec22d117ca0b489500b4d0a0 (master)
 	NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/commit/ba830583e6a8e9a78f09e2d723813c03142b11f6 (server-21.1-branch)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[13 Aug 2026] DLA-4738-1 xorg-server - security update
+	{CVE-2022-49737 CVE-2026-33999 CVE-2026-34000 CVE-2026-34001 CVE-2026-34002 CVE-2026-34003 CVE-2026-50256 CVE-2026-50257 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262 CVE-2026-50263 CVE-2026-50264}
+	[bullseye] - xorg-server 2:1.20.11-1+deb11u18
 [13 Aug 2026] DLA-4737-1 xorg-server - security update
 	{CVE-2022-49737 CVE-2026-50256 CVE-2026-50257 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262 CVE-2026-50263 CVE-2026-50264}
 	[bookworm] - xorg-server 2:21.1.7-3+deb12u13



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e004f7442237245efff58d3bcb66ac047368df6e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e004f7442237245efff58d3bcb66ac047368df6e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/67dac76f/attachment.htm>


More information about the debian-security-tracker-commits mailing list