ALSA-2026:38489

Source
https://errata.almalinux.org/10/ALSA-2026-38489.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:38489.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALSA-2026:38489
Related
Published
2026-07-13T00:00:00Z
Modified
2026-08-13T11:45:03.230089462Z
Summary
Important: xorg-x11-server-Xwayland security update
Details

Xwayland is an X server for running X clients under Wayland.

Security Fix(es):

  • xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow (CVE-2026-55999)
  • X.org: xorg-x11-server: GLX contextTags Use-After-Free in CommonMakeCurrent() (CVE-2026-56000)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:10 / xorg-x11-server-Xwayland

Package

Name
xorg-x11-server-Xwayland
Purl
pkg:rpm/almalinux/xorg-x11-server-Xwayland

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.1.9-4.el10_2.3

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:38489.json"

AlmaLinux:10 / xorg-x11-server-Xwayland-devel

Package

Name
xorg-x11-server-Xwayland-devel
Purl
pkg:rpm/almalinux/xorg-x11-server-Xwayland-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.1.9-4.el10_2.3

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:38489.json"