Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:21699 - Security Advisory
Issued:
2026-05-28
Updated:
2026-05-28

RHSA-2026:21699 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: xorg-x11-server security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for xorg-x11-server is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.

Security Fix(es):

  • xorg: xwayland: X.Org X server: Denial of Service via integer underflow in XKB compatibility map handling (CVE-2026-33999)
  • xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing. (CVE-2026-34000)
  • xorg: xwayland: X.Org X server: Use-after-free vulnerability leads to server crash and potential memory corruption (CVE-2026-34001)
  • xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling (CVE-2026-34002)
  • xorg: xwayland: X.Org X server: Information exposure and denial of service via out-of-bounds memory access (CVE-2026-34003)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2451106 - CVE-2026-33999 xorg: xwayland: X.Org X server: Denial of Service via integer underflow in XKB compatibility map handling
  • BZ - 2451107 - CVE-2026-34000 xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.
  • BZ - 2451109 - CVE-2026-34001 xorg: xwayland: X.Org X server: Use-after-free vulnerability leads to server crash and potential memory corruption
  • BZ - 2451112 - CVE-2026-34002 xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling
  • BZ - 2451113 - CVE-2026-34003 xorg: xwayland: X.Org X server: Information exposure and denial of service via out-of-bounds memory access

CVEs

  • CVE-2026-33999
  • CVE-2026-34000
  • CVE-2026-34001
  • CVE-2026-34002
  • CVE-2026-34003

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
xorg-x11-server-1.20.11-13.el9_0.src.rpm SHA-256: 8d22106b858c854d5005970eafeef3e5c600a14a4f53527ef5bb46f6f70f66ff
ppc64le
xorg-x11-server-Xdmx-1.20.11-13.el9_0.ppc64le.rpm SHA-256: be052dd8def2414c411b3660f4c69cbfa0e74b9a32f204248d335b7aa092da54
xorg-x11-server-Xdmx-debuginfo-1.20.11-13.el9_0.ppc64le.rpm SHA-256: eacf88d0ca4921e541602a747466d44b316814ddb3f8fa7a777f50a4733573f0
xorg-x11-server-Xephyr-1.20.11-13.el9_0.ppc64le.rpm SHA-256: 5252267af723d1cc1a918795a0b41f50e3a27b3862f27f1c246449c6aa608ec4
xorg-x11-server-Xephyr-debuginfo-1.20.11-13.el9_0.ppc64le.rpm SHA-256: f5bf47a3ef86b102bb80db7ecd848729d1326ac75feee315a5e5ae09bcfbbc1e
xorg-x11-server-Xnest-1.20.11-13.el9_0.ppc64le.rpm SHA-256: af3504d7b4d151860de976e1a65bfb0861b87ef8fe4b8f9124b444bf0df029d3
xorg-x11-server-Xnest-debuginfo-1.20.11-13.el9_0.ppc64le.rpm SHA-256: ed7f070006d9bd9374a4c2a3740a246c82c11bc43ceb19348474755c4528880d
xorg-x11-server-Xorg-1.20.11-13.el9_0.ppc64le.rpm SHA-256: c220db27439169505cbea75e551fe63ea38b938892a21c267029c60fa7e42815
xorg-x11-server-Xorg-debuginfo-1.20.11-13.el9_0.ppc64le.rpm SHA-256: 7e43d2b1e78d252b6f07bcac445184f443b4f737352bb4d819e115158e24caef
xorg-x11-server-Xvfb-1.20.11-13.el9_0.ppc64le.rpm SHA-256: 45fdb1011e125d0aa6c927b892f7c5aeacb5635a8a6c263bcad650f1eea5198a
xorg-x11-server-Xvfb-debuginfo-1.20.11-13.el9_0.ppc64le.rpm SHA-256: 350077de32147f75a08e907d5c9f94e24c627c8566ffee18da9a1efbd84e0bab
xorg-x11-server-common-1.20.11-13.el9_0.ppc64le.rpm SHA-256: f4d6ac10fdd4efbcc55f1bac76e6c16dcc872139b19bb4575692f6f2f5b721e5
xorg-x11-server-debuginfo-1.20.11-13.el9_0.ppc64le.rpm SHA-256: 2a216db6882b21edf0c2b4a8a9fee66cdb7355b1a2b241877cba0c7e92f9ed93
xorg-x11-server-debugsource-1.20.11-13.el9_0.ppc64le.rpm SHA-256: a38e27ff1bb6ce5bd4fe3e68841204c1d634bd5bd21077dc77cfcd53dd413788

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
xorg-x11-server-1.20.11-13.el9_0.src.rpm SHA-256: 8d22106b858c854d5005970eafeef3e5c600a14a4f53527ef5bb46f6f70f66ff
x86_64
xorg-x11-server-Xdmx-1.20.11-13.el9_0.x86_64.rpm SHA-256: 91bc8fac87f32938bf2be74f1973151e98bc7736c06360589878ff82e31ca540
xorg-x11-server-Xdmx-debuginfo-1.20.11-13.el9_0.x86_64.rpm SHA-256: e57569c7be267461f23ae89f448c92659d4f7d99b9ccdc2b8aac82483b683dd5
xorg-x11-server-Xephyr-1.20.11-13.el9_0.x86_64.rpm SHA-256: 06038f8e46d0b75c7819a051bd842f6b5eff5e0d0f8a9ca3f0bf0356873eb775
xorg-x11-server-Xephyr-debuginfo-1.20.11-13.el9_0.x86_64.rpm SHA-256: 35a4e002b6ba58ce43ad8c2417c5e6cd1bfddf50297c7c3fe092a8d7d076e0f5
xorg-x11-server-Xnest-1.20.11-13.el9_0.x86_64.rpm SHA-256: e8402ee364929bbb980a38f8842ff543b5b71a37e72d570c00ea7df43cbff189
xorg-x11-server-Xnest-debuginfo-1.20.11-13.el9_0.x86_64.rpm SHA-256: aac6ed4442c213f9f50bb0d6bb06cdd7661c22b23b0528d1a678edf1574e7289
xorg-x11-server-Xorg-1.20.11-13.el9_0.x86_64.rpm SHA-256: eb4aeddc5722e8bff2e0264c90527a382bc1fe5ce7b52fd3bb60b5b77ce2935b
xorg-x11-server-Xorg-debuginfo-1.20.11-13.el9_0.x86_64.rpm SHA-256: 9bb25895f5c9906c91fc304acf98616029e319473cb72d1da19aa584cc573a4e
xorg-x11-server-Xvfb-1.20.11-13.el9_0.x86_64.rpm SHA-256: 895e2a590c566c3360d623d6d75cb64c695cec4716b073c586d567aa4f14bf52
xorg-x11-server-Xvfb-debuginfo-1.20.11-13.el9_0.x86_64.rpm SHA-256: 0b00326b2ab061a4031a4c9c18bb0eb5d2f3593790aa194c7ee8eb9ae4b960e2
xorg-x11-server-common-1.20.11-13.el9_0.x86_64.rpm SHA-256: 8c79649c5ac1938dd5d81a167326205c204d4448d66e67c3b76f763c93b86585
xorg-x11-server-debuginfo-1.20.11-13.el9_0.x86_64.rpm SHA-256: 93c6ad34cdd72254d66466c7042feedc1c4530ec4b83410be8ce1a5bcabeab3f
xorg-x11-server-debugsource-1.20.11-13.el9_0.x86_64.rpm SHA-256: 4b9db7c9774e619de7ceeb41296fd73c7b5cbd85ae0df82b28e7715d77281ec8

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
xorg-x11-server-1.20.11-13.el9_0.src.rpm SHA-256: 8d22106b858c854d5005970eafeef3e5c600a14a4f53527ef5bb46f6f70f66ff
aarch64
xorg-x11-server-Xdmx-1.20.11-13.el9_0.aarch64.rpm SHA-256: 9aedd39767e14adc9e16c8d7d23d94a78dbb203ef098446e385f673531003352
xorg-x11-server-Xdmx-debuginfo-1.20.11-13.el9_0.aarch64.rpm SHA-256: 2dfc6ceeb271ebca79eaa99f013b5c3aee1ea9a8131d23dcaa0982c9b58f0c58
xorg-x11-server-Xephyr-1.20.11-13.el9_0.aarch64.rpm SHA-256: e878d18a121fdd7fa5b80343bac19aa588cacc9a288973202fe1980ea751d736
xorg-x11-server-Xephyr-debuginfo-1.20.11-13.el9_0.aarch64.rpm SHA-256: 7de33aa85024289de54d5c386721bc41dc97282d81bd038754664d3e57c19bab
xorg-x11-server-Xnest-1.20.11-13.el9_0.aarch64.rpm SHA-256: de273c1a69435d23c272e3cce4854d1fa5de1036a6d633cd96d623c9e1f8c2c7
xorg-x11-server-Xnest-debuginfo-1.20.11-13.el9_0.aarch64.rpm SHA-256: d426148b5a873276349fc05c6366cd996fa7ef07c9bbd70ba116f89628354498
xorg-x11-server-Xorg-1.20.11-13.el9_0.aarch64.rpm SHA-256: dc0bae7c9bad5ceb2cdb0113318772d2ebf4a5fbcd68e324d54c29d231b93383
xorg-x11-server-Xorg-debuginfo-1.20.11-13.el9_0.aarch64.rpm SHA-256: d78244a5de2b2e968c9924b89978d8b4570ddbe35a0243a16ccf83379a64ff99
xorg-x11-server-Xvfb-1.20.11-13.el9_0.aarch64.rpm SHA-256: ac52a62e6cd2d7c9598617a8bc2ec9f941887ae004e94dfec72def8ce0a7a703
xorg-x11-server-Xvfb-debuginfo-1.20.11-13.el9_0.aarch64.rpm SHA-256: a1b6ce7cd3ca10a0117c2a931759b2adb8490756daff63850b7dbf4fc8ff2dfa
xorg-x11-server-common-1.20.11-13.el9_0.aarch64.rpm SHA-256: 7d119d2677d3050da71f93ba7d8363042295924a632284d89e2dfe2aa9addf63
xorg-x11-server-debuginfo-1.20.11-13.el9_0.aarch64.rpm SHA-256: 8dd50e4e5a75240998f34f179e8eaebe7fd6261f1d1c48955e232df713545957
xorg-x11-server-debugsource-1.20.11-13.el9_0.aarch64.rpm SHA-256: f1d16a6c882078935fdefc7f7a08b839ec89f3a60ab1b90cf039482d49a208c7

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
xorg-x11-server-1.20.11-13.el9_0.src.rpm SHA-256: 8d22106b858c854d5005970eafeef3e5c600a14a4f53527ef5bb46f6f70f66ff
s390x
xorg-x11-server-Xdmx-1.20.11-13.el9_0.s390x.rpm SHA-256: 85365760bcbe636f1c1667311fbcadab1ba1f867b7c742e3fc4e3a88dea9fe7b
xorg-x11-server-Xdmx-debuginfo-1.20.11-13.el9_0.s390x.rpm SHA-256: 004cebb6c83a6789af18ac3e429ff20bc5ea481b4218951a7595d51622df4c0b
xorg-x11-server-Xephyr-1.20.11-13.el9_0.s390x.rpm SHA-256: e73fbcee8c288d838a7d7a46fc69df5c29b967bb8e597361616d773397c89db2
xorg-x11-server-Xephyr-debuginfo-1.20.11-13.el9_0.s390x.rpm SHA-256: 6395ec80ed9628962dcd6329709537fa0fa4984979cf13b27cd62f4859b06ce0
xorg-x11-server-Xnest-1.20.11-13.el9_0.s390x.rpm SHA-256: a113064c046ec06e0746b8da2825c8e9d523e9721a6ae5f05e05a376c8605313
xorg-x11-server-Xnest-debuginfo-1.20.11-13.el9_0.s390x.rpm SHA-256: 51d79b7cc6fd252b2efc1428881f37ebc521eb854856378b6c485c2232b81bc9
xorg-x11-server-Xorg-1.20.11-13.el9_0.s390x.rpm SHA-256: 3bee2ca0a82db99c80a733b36657dc9466186cd99ec05481d480bffdfd6c5c23
xorg-x11-server-Xorg-debuginfo-1.20.11-13.el9_0.s390x.rpm SHA-256: c92d9f03de8f137f28adb9b309cac1e92aaacd51969edcc08a0575fabff886dc
xorg-x11-server-Xvfb-1.20.11-13.el9_0.s390x.rpm SHA-256: a918c69a7ca5b8cfe18a9111767c880e1986fd83b06c1dcc5d24ecab2ae5522d
xorg-x11-server-Xvfb-debuginfo-1.20.11-13.el9_0.s390x.rpm SHA-256: bf5087da0fabc668df5752207fd2a08d042403e3561c02c8e51e012baa5d7113
xorg-x11-server-common-1.20.11-13.el9_0.s390x.rpm SHA-256: 919ba9fc393ee198a7551350c3d56148b6943a4b2132bf5e6655c0ebf65a6d28
xorg-x11-server-debuginfo-1.20.11-13.el9_0.s390x.rpm SHA-256: f9521f11da9d9e8320b8d4ba932d338572dfe8717b403c1de828dc6001ac62f5
xorg-x11-server-debugsource-1.20.11-13.el9_0.s390x.rpm SHA-256: 1fc3c78352ae75b67d7d77b99b4387cd30a9c8edeaa035cc248a56b79c418638

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility