Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check both X.Org X server and Xwayland where applicable, then use your Linux distribution’s security notice to determine whether your installed packages are fixed. The latest entry on the X.Org security index, dated July 8, 2026, lists xorg-server 21.1.24 and Xwayland 24.1.13 as fixed upstream versions. Those thresholds do not by themselves establish whether a distribution package is vulnerable: distributors may package or backport fixes differently.

What the latest X.Org security entry says

The July 8, 2026 entry on the X.Org security index covers X.Org X server versions before 21.1.24 and Xwayland versions before 24.1.13. It lists CVE-2026-55999, a glamor Font Atlas heap buffer overflow, and CVE-2026-56000, a GLX contextTags use-after-free. The index names xorg-server 21.1.24 and Xwayland 24.1.13 as fixed upstream releases.

The title’s “a dozen” is not a useful description of that July entry by itself. The index organizes advisories by date and component, and its June 2026 record appears to repeat a CVE identifier. Check the linked advisory records for the exact scope and issue count rather than treating a headline count as a vulnerability total.

Check whether your session uses X.Org X server, Xwayland, or both

X.Org X server and Xwayland are separate components, with different version numbers and fixed thresholds. A system may have one or both installed, and the version of one does not establish the status of the other. Check the server relevant to the session or application you are assessing, as well as installed package details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

X.Org’s versioning documentation describes checking server information from a client such as xdpyinfo. The reported VendorRelease value corresponds to the server version in the usual case, and logs or the server’s -version option may also show version information. Some releases did not report this value correctly, so use it to identify an upstream version—not as proof that your distribution package lacks a fix.

Use the version result safely

  1. Inspect the running server. From a graphical session, run xdpyinfo and look for the server vendor and release information. If the command is unavailable or the output is unclear, consult the session’s logs or package details; the server’s -version option is another possible source when supported.
  2. Identify the relevant component. Determine whether the version you found is for X.Org X server or Xwayland. Check both if both are relevant to your system.
  3. Compare with the upstream advisory. For the July 8, 2026 entry, the listed fixed upstream thresholds are xorg-server 21.1.24 and Xwayland 24.1.13. The index also lists earlier batches, including April 14, 2026 fixes in xorg-server 21.1.22 and Xwayland 24.1.10, and June 2, 2026 fixes in xorg-server 21.1.23 and Xwayland 24.1.12. Older unaddressed advisories may also matter.
  4. Confirm package status with your distributor. Check the operating system or distribution security advisory for the installed package and revision. A package version that looks older than the upstream threshold may include backported fixes; only the vendor’s security status can resolve that for its package.
  5. Install updates through the supported system mechanism. Apply the available operating-system updates and follow the distributor’s instructions if a package is held, unsupported, or not offered an update.

Why your package version may not match X.Org’s number

The X.Org project says the full software stack is no longer released as one current bundle: modules are released independently. Its guidance is to obtain X software through the operating system or distribution vendor; X.Org does not provide binaries. As a result, a distribution package’s displayed version or revision may not map directly to an upstream release number, and a distributor may backport a security correction without adopting the corresponding upstream version string. The package’s vendor advisory is the right place to verify its fix status.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Earlier 2026 fixes may also matter

The security index lists several 2026 server and Xwayland advisory batches. A system that has missed multiple update cycles should not check only the newest threshold:

  • June 2, 2026: Upstream thresholds before xorg-server 21.1.23 and Xwayland 24.1.12; the index describes XKB, XSYNC, GLX, and DRI2 issues, including out-of-bounds access, use-after-free, and information disclosure.
  • April 14, 2026: Thresholds before xorg-server 21.1.22 and Xwayland 24.1.10, including XKB and XSYNC flaws.
  • Earlier listed batches: October 2025 fixes in xorg-server 21.1.19 and Xwayland 24.1.9; June 2025 fixes in 21.1.17 and 24.1.7; and February 2025 fixes in 21.1.16 and 24.1.6.

The index cautions that advisories are ordered by the most recent release they affect and that many issues also affect older releases, sometimes back to when the relevant functionality was introduced. Use the linked advisory for the issue-specific affected-release details, and your distributor’s notice for the status of its packages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.