Linuxsecurity Critical Vulnerabilities in xorg-server Affecting Slackware and SUSE Systems
Article Content
- •CVE-2026-55999 and CVE-2026-56000 patched in xorg-server for Slackware and SUSE.
- •Heap buffer overflow and use-after-free vulnerabilities can be exploited by malicious files or clients.
- •Immediate patching is recommended to protect affected systems from potential attacks.
Recent updates have addressed critical vulnerabilities in xorg-server affecting Slackware and SUSE systems. The vulnerabilities include CVE-2026-55999, a heap buffer overflow due to a missing bounds check in `glamor_font_get`, and CVE-2026-56000, a use-after-free issue in `CommonMakeCurrent`. These vulnerabilities can be exploited by processing malicious PCF files or through interactions with malicious clients creating GLX contexts. The flaws were confirmed and patched on July 8, 2026, with significant implications for users of Slackware 15.0 and SUSE Linux Enterprise Server. Users are advised to apply the patches immediately to mitigate potential exploitation risks. The vulnerabilities are rated as important, indicating a serious risk to system integrity and security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track SuSE and CVE-2026-55999 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…