[CLSA-2026:1790925629] Fix CVE(s): CVE-2026-88806
Type:
security
Severity:
Important
Release date:
2026-10-02 07:20:40 UTC
Description:
* SECURITY UPDATE: out-of-bounds write in XkbGetMap reply handling - debian/patches/CVE-2026-88806.patch: check that firstKeyAct + nKeyActs does not exceed max_key_code + 1 in _XkbReadKeyActions() before writing into key_sym_map - CVE-2026-88806
CVEs fixed:
Updated packages:
  • libx11-6_1.7.2-1+deb11u2+tuxcare.els1_amd64.deb
    sha:6f8a36c45faaedb86aa66b61622878fa0820d4c8
  • libx11-data_1.7.2-1+deb11u2+tuxcare.els1_all.deb
    sha:28e0668eda6afd77267d2d3ec391cfba1da6e2e3
  • libx11-dev_1.7.2-1+deb11u2+tuxcare.els1_amd64.deb
    sha:600922ef8d18b7f0ca5f63896d02e93a45390784
  • libx11-doc_1.7.2-1+deb11u2+tuxcare.els1_all.deb
    sha:d5832064b15eeb47c4e047964ea5ba0a1ba6f6af
  • libx11-xcb-dev_1.7.2-1+deb11u2+tuxcare.els1_amd64.deb
    sha:b7ae35d8d59bef1712e45ee70c809b46cc7c2890
  • libx11-xcb1_1.7.2-1+deb11u2+tuxcare.els1_amd64.deb
    sha:4279e2f800d0f7a7edac93505a924f85eaaef18c
  • libx11-6_1.7.2-1+deb11u2+tuxcare.els1_arm64.deb
    sha:f5cb31923af754a2dd5ce38658768b513ef55733
  • libx11-dev_1.7.2-1+deb11u2+tuxcare.els1_arm64.deb
    sha:a2b323e7ac907826bd619c0bf706a06e91cf1f0a
  • libx11-xcb-dev_1.7.2-1+deb11u2+tuxcare.els1_arm64.deb
    sha:c9108d043e5e8de1209851fb6bcd1cb74e4d6498
  • libx11-xcb1_1.7.2-1+deb11u2+tuxcare.els1_arm64.deb
    sha:21e3c34b41b883bd5089d90b96d0ef1df1f17130
  • libx11-6_1.7.2-1+deb11u2+tuxcare.els1_armel.deb
    sha:95a9c88258259911ce3ab75aa36a502b0809cc6f
  • libx11-dev_1.7.2-1+deb11u2+tuxcare.els1_armel.deb
    sha:c7cef22b4a36a4236439c33bbe0ea22b166916f0
  • libx11-xcb-dev_1.7.2-1+deb11u2+tuxcare.els1_armel.deb
    sha:453e75821ed124dbda8a8649fc3132e188b24f7e
  • libx11-xcb1_1.7.2-1+deb11u2+tuxcare.els1_armel.deb
    sha:7803b86192d121bf5ccf60df443beddb895ee691
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.