SUSE-CU-2026:6852-1: Security update of suse/kiosk/xorg

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Jul 9 07:46:48 UTC 2026


SUSE Container Update Advisory: suse/kiosk/xorg
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:6852-1
Container Tags        : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.11 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar
Container Release     : 82.11
Severity              : important
Type                  : security
References            : 1268893 1268894 1269018 1269019 1269020 CVE-2026-55999 CVE-2026-56000
                        CVE-2026-56001 CVE-2026-56002 CVE-2026-56003 
-----------------------------------------------------------------

The container suse/kiosk/xorg was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2788-1
Released:    Wed Jul  8 09:22:08 2026
Summary:     Security update for xorg-x11-server
Type:        security
Severity:    important
References:  1268893,1268894,CVE-2026-55999,CVE-2026-56000
This update for xorg-x11-server fixes the following issues

- CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from
  a malicious PCF file is processed (bsc#1268893).
- CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an
  interaction with a malicious client creating GLX contexts happens (bsc#1268894).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2794-1
Released:    Wed Jul  8 10:07:50 2026
Summary:     Security update for libXfont2
Type:        security
Severity:    important
References:  1269018,1269019,1269020,CVE-2026-56001,CVE-2026-56002,CVE-2026-56003
This update for libXfont2 fixes the following issues

- CVE-2026-56001: integer overflow in `BitmapScaleBitmaps` can lead to a heap buffer overflow (bsc#1269018).
- CVE-2026-56002: insufficient checks in `pcfReadFont` can lead to a heap buffer overflow (bsc#1269019).
- CVE-2026-56003: missing bounds check in `ComputeScaledProperties` can lead to a heap buffer overflow (bsc#1269020).


The following package changes have been done:

- libXfont2-2-2.0.3-150000.3.3.1 updated
- xorg-x11-server-Xvfb-21.1.15-150700.5.22.1 updated
- xorg-x11-server-21.1.15-150700.5.22.1 updated


More information about the sle-container-updates mailing list