X.Org Security Advisory: Multiple Vulnerabilities Fixed in X Server 21.1.19 and Xwayland 24.1.9
By
birdculture
Reliable enough to start your morning with. Toast it again tomorrow.
Summary
X.Org has released security advisories for multiple vulnerabilities in X.Org X server (prior to version 21.1.18) and Xwayland (prior to version 24.1.8). The security issues include CVE-2025-62229 (use-after-free in XPresentNoti) and other unspecified vulnerabilities. Security fixes are available in xorg-server-21.1.19 and xwayland-24.1.9. The advisory provides technical details about the vulnerabilities and recommends immediate updates to the patched versions.
Key quotes
· 4 pulledMultiple issues have been found in the X server and Xwayland implementations published by X.Org for which we are releasing security fixes for in xorg-server-21.1.19 and xwayland-24.1.9.
1) CVE-2025-62229: Use-after-free in XPresentNoti
Issues in X.Org X server prior to 21.1.18 and Xwayland prior to 24.1.8
X.Org Security Advisory: October 28, 2025
Article URL: https://lists.x.org/archives/xorg-announce/2025-October/003635.html
Comments URL: https://news.ycombinator.com/item?id=45790015
Points: 14
# Comments: 2
You might also wanna read
How a botnet abused my open source project's cloud version to phish 14,000 people
The author, who runs an open source project management tool called Kaneo, discovered that a botnet had abused the hosted cloud version of th
AI security audit of FreeBSD kernel reveals 15 bugs including RCEs and a hypervisor escape
An AI audit of FreeBSD uncovered 15 kernel bugs, including 3 remote code execution vulnerabilities, 5 local privilege escalation flaws, and

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Composer and Packagist Introduce New Supply Chain Security Measures After PHP Ecosystem Attacks
Composer and Packagist.org are implementing new security measures to combat rising software supply chain attacks targeting the PHP open-sour
blog.packagist.com·4d agoComposer and Packagist Introduce New Supply Chain Security Measures After PHP Ecosystem Attacks
Composer and Packagist.org are implementing new security measures to combat rising software supply chain attacks targeting the PHP open-sour
blog.packagist.com·4d agoCritical "BadHost" vulnerability in Starlette framework puts millions of AI agents at risk
A critical vulnerability called "BadHost" has been discovered in Starlette, an open source ASGI framework with 325 million weekly downloads.
arstechnica.com·5d ago