SUSE-CU-2026:6852-1: Security update of suse/kiosk/xorg
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Jul 9 07:46:48 UTC 2026
SUSE Container Update Advisory: suse/kiosk/xorg
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:6852-1
Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.11 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar
Container Release : 82.11
Severity : important
Type : security
References : 1268893 1268894 1269018 1269019 1269020 CVE-2026-55999 CVE-2026-56000
CVE-2026-56001 CVE-2026-56002 CVE-2026-56003
-----------------------------------------------------------------
The container suse/kiosk/xorg was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2788-1
Released: Wed Jul 8 09:22:08 2026
Summary: Security update for xorg-x11-server
Type: security
Severity: important
References: 1268893,1268894,CVE-2026-55999,CVE-2026-56000
This update for xorg-x11-server fixes the following issues
- CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from
a malicious PCF file is processed (bsc#1268893).
- CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an
interaction with a malicious client creating GLX contexts happens (bsc#1268894).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2794-1
Released: Wed Jul 8 10:07:50 2026
Summary: Security update for libXfont2
Type: security
Severity: important
References: 1269018,1269019,1269020,CVE-2026-56001,CVE-2026-56002,CVE-2026-56003
This update for libXfont2 fixes the following issues
- CVE-2026-56001: integer overflow in `BitmapScaleBitmaps` can lead to a heap buffer overflow (bsc#1269018).
- CVE-2026-56002: insufficient checks in `pcfReadFont` can lead to a heap buffer overflow (bsc#1269019).
- CVE-2026-56003: missing bounds check in `ComputeScaledProperties` can lead to a heap buffer overflow (bsc#1269020).
The following package changes have been done:
- libXfont2-2-2.0.3-150000.3.3.1 updated
- xorg-x11-server-Xvfb-21.1.15-150700.5.22.1 updated
- xorg-x11-server-21.1.15-150700.5.22.1 updated
More information about the sle-container-updates
mailing list