Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0036 - Security Advisory
Issued:
2026-01-05
Updated:
2026-01-05

RHSA-2026:0036 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: xorg-x11-server-Xwayland security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for xorg-x11-server-Xwayland is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Xwayland is an X server for running X clients under Wayland.

Security Fix(es):

  • xorg: xmayland: Use-after-free in XPresentNotify structure creation (CVE-2025-62229)
  • xorg: xwayland: Use-after-free in Xkb client resource removal (CVE-2025-62230)
  • xorg: xmayland: Value overflow in XkbSetCompatMap() (CVE-2025-62231)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2402649 - CVE-2025-62229 xorg: xmayland: Use-after-free in XPresentNotify structure creation
  • BZ - 2402653 - CVE-2025-62230 xorg: xwayland: Use-after-free in Xkb client resource removal
  • BZ - 2402660 - CVE-2025-62231 xorg: xmayland: Value overflow in XkbSetCompatMap()

CVEs

  • CVE-2025-62229
  • CVE-2025-62230
  • CVE-2025-62231

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
xorg-x11-server-Xwayland-21.1.3-9.el9_2.src.rpm SHA-256: cbf8c422c0f1c1d11afdf8bf7854a0ae6aace349a36a166051b0949212054d6b
x86_64
xorg-x11-server-Xwayland-21.1.3-9.el9_2.x86_64.rpm SHA-256: 4cd7b2c8fd32195e99024ed9c79b5faf7cc5bbd74e5d1fd0098a4d61fb32227a
xorg-x11-server-Xwayland-debuginfo-21.1.3-9.el9_2.x86_64.rpm SHA-256: eaa120ff556df33e6a5968d4d5d040cce08e9d4bad9d23e5325acd3c287d7b01
xorg-x11-server-Xwayland-debugsource-21.1.3-9.el9_2.x86_64.rpm SHA-256: 3722aed32bc228c1d32b7e2a9e2548236774e38b43372a02255a8e5411219f15

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
xorg-x11-server-Xwayland-21.1.3-9.el9_2.src.rpm SHA-256: cbf8c422c0f1c1d11afdf8bf7854a0ae6aace349a36a166051b0949212054d6b
ppc64le
xorg-x11-server-Xwayland-21.1.3-9.el9_2.ppc64le.rpm SHA-256: 746f3a498fae715ef974780c1c6b7128e6299bf6a3e39ac6f2e382bc9985ceeb
xorg-x11-server-Xwayland-debuginfo-21.1.3-9.el9_2.ppc64le.rpm SHA-256: df2776763c6017a261b6f5ad11cfe1c69571ab5468c3d4bfee38e5d4c1a323be
xorg-x11-server-Xwayland-debugsource-21.1.3-9.el9_2.ppc64le.rpm SHA-256: ca7f87676c58b6b1cd45e5119da7fb2757f8f74dc8d96455e97dd1e6ce849e81

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
xorg-x11-server-Xwayland-21.1.3-9.el9_2.src.rpm SHA-256: cbf8c422c0f1c1d11afdf8bf7854a0ae6aace349a36a166051b0949212054d6b
x86_64
xorg-x11-server-Xwayland-21.1.3-9.el9_2.x86_64.rpm SHA-256: 4cd7b2c8fd32195e99024ed9c79b5faf7cc5bbd74e5d1fd0098a4d61fb32227a
xorg-x11-server-Xwayland-debuginfo-21.1.3-9.el9_2.x86_64.rpm SHA-256: eaa120ff556df33e6a5968d4d5d040cce08e9d4bad9d23e5325acd3c287d7b01
xorg-x11-server-Xwayland-debugsource-21.1.3-9.el9_2.x86_64.rpm SHA-256: 3722aed32bc228c1d32b7e2a9e2548236774e38b43372a02255a8e5411219f15

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
xorg-x11-server-Xwayland-21.1.3-9.el9_2.src.rpm SHA-256: cbf8c422c0f1c1d11afdf8bf7854a0ae6aace349a36a166051b0949212054d6b
aarch64
xorg-x11-server-Xwayland-21.1.3-9.el9_2.aarch64.rpm SHA-256: e7d2c21b6b05c5b14e188e416b19ad7da50e034ff17323613ae04d4e1f560196
xorg-x11-server-Xwayland-debuginfo-21.1.3-9.el9_2.aarch64.rpm SHA-256: 9398bcad18147b39d27340e164188a51a497d2b59f21a341de73f54aca536d4a
xorg-x11-server-Xwayland-debugsource-21.1.3-9.el9_2.aarch64.rpm SHA-256: 2c38c7f1ae0905df7ab8f92a1a36cf10b14db92dc11b2862e84c76c2995bf7d1

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
xorg-x11-server-Xwayland-21.1.3-9.el9_2.src.rpm SHA-256: cbf8c422c0f1c1d11afdf8bf7854a0ae6aace349a36a166051b0949212054d6b
s390x
xorg-x11-server-Xwayland-21.1.3-9.el9_2.s390x.rpm SHA-256: 8f647808c95ad44962fc0f1ee54bcc272b602859313b8e0c49183e9fcfaa2fd7
xorg-x11-server-Xwayland-debuginfo-21.1.3-9.el9_2.s390x.rpm SHA-256: f3521e99c9ded0c7c4bd8bb7d9635fad429c527c6f3608b08c0e79b27f37469b
xorg-x11-server-Xwayland-debugsource-21.1.3-9.el9_2.s390x.rpm SHA-256: 345bcb208052f8f6511a0a454bafd1e706c4b864b2247c9335cb597c39c72d08

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility