{"id":"CLSA-2026-1778110872","summary":"xorg-x11-server-Xwayland: Fix of 3 CVEs","details":"- CVE-2024-0408: fix XSELinux crash by calling XACE hooks when creating GLX buffers\n- CVE-2025-49175: fix out-of-bounds read in animated cursor creation when client provides zero cursors\n- CVE-2025-49178: fix possible client request hang caused by leftover bytes-to-ignore when sharing input buffer","modified":"2026-05-27T11:17:23.549339936Z","published":"2026-05-06T23:41:17Z","upstream":["CVE-2024-0408","CVE-2025-49175","CVE-2025-49178"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2026-1778110872.html"}],"affected":[{"package":{"name":"xorg-x11-server-Xwayland","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/xorg-x11-server-Xwayland?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"21.1.3-7.el9.tuxcare.els15"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1778110872.json"}},{"package":{"name":"xorg-x11-server-Xwayland-devel","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/xorg-x11-server-Xwayland-devel?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"21.1.3-7.el9.tuxcare.els15"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1778110872.json"}}],"schema_version":"1.7.5"}