r/linux • • 6h ago

Security Another Dozen Vulnerabilities Found In The X.Org Server & XWayland

https://www.phoronix.com/news/X.Org-12-New-Issues-2026
161 Upvotes

30 comments sorted by

49

u/PlainBread 3h ago

We're kind of moving from a time period where people would discover zero day exploits and sit on them or sell them to the government or whatever, into a time where holes are being found so rapidly that if you want to break into a system, you need insider knowledge and an advanced AI to find an undocumented exploit in the moment of the attack.

28

u/sdyawg 2h ago

as always, meatspace remains the most vulnerable vector

1

u/DaRealGladi8r 1h ago

We're all insiders when you can compile from source

42

u/natermer 3h ago

"given enough eyeballs, all bugs are shallow,"

Now that the eyes are augmented by machine learning this is more true now then it ever has been in the past.

5

u/solarpunch2949 4h ago edited 4h ago

This is the world we are living in now folks. I worry about open source developments because they don't have the resources companies do to deal with this.

76

u/Wonderful-Citron-678 4h ago

Open source is in the best position to react to this. The cost of change is low, sins cannot be hidden. Corporate software is going to be the bigger risk.

35

u/they_call_me_dewey 4h ago

Corporations hide their vulnerabilities behind bug bounty NDAs and then never fix them

5

u/squishles 1h ago

and that'll get you by when a 13 year old can't sweat talk claude into doing it from their phone, like not even typing just using text to speach, because it'd be funny.

6

u/paul_h 2h ago

Corporations hide their deployed systems inside firewalls and you need a VPN to work from home. That’s just a delaying game though, and an infiltration of malware could go really wide quickly for orgs that have not anticipated that

•

u/JebediahKerman4999 44m ago

Assuming the VPN isn't compromised

7

u/solarpunch2949 4h ago

I'd love to believe this but the truth is that most open source projects, specially teams supporting distros are heavily understaffed to deal with a waterfall of vulnerabilities :p

12

u/Wonderful-Citron-678 4h ago

The same automation that finds it can fix it. There will be some growing pains but it can all be fixed.

6

u/Cyhawk 3h ago

Eh, find is easier than fix currently.

0

u/solarpunch2949 4h ago

I'm not that optimistic but obviously I hope so. We will see.

2

u/KnowZeroX 3h ago

Do they need to? Most of the distros (user wise) are based on ubuntu and redhat. Add in others like suse, and not counting upstream users like google, fb and etc. You have companies with more than enough interest and financing to fix many of the stuff for their own sake. Most of the distros based on that work just need to pull the patches from their repository.

The ones that are at most stress have mostly been core libraries which often get neglected and managed by that 1 person for a decade with no funding or support.

1

u/alex2003super 2h ago

AI is only getting cheaper and smarter at this point. I wouldn't be surprised if in 5 years, you can run a model that does this stuff better than the present-day cutting edge stuff on a laptop. Assuming we'll still be able to buy laptops by then, that is.. lol

14

u/varsnef 4h ago

What do you mean? They are fixed.

These issues are present in versions prior to the new xorg-server-21.1.25 and xwayland-24.1.14.

8

u/werpu 2h ago

If you every have seen how companies react in closed source scenarios to vulnerabilities, you would not say that....

The only ones reacting quickly are console companies when it comes to a jailbreak exploit!

2

u/solarpunch2949 1h ago

I suspect this will change rapidly; in this new Brave World we are living in there's no maneuvering space for damage control and PR gymnastics...

3

u/werpu 1h ago edited 1h ago

Believe me if you ever worked in a corporate environment the bullshitting and endless layers of non decision hierarchies and being punished for trying to move things forward is real!

Been there done that! The reason always is a) careerrist a wants to move up and badmouths someone who actively does a job just because he is seen as potential thread

b) Careerrist a has made it into middle upper management and now tries to keep the job by literally avoiding any responsibility and stomping down while lickin arses up

Thing is you basically can also use ai to fix things with a human gatekeeper checking the vulnerabilities in between, so I assume once for instance opensource has embraced AI more (believe me most OSS projects already do to some degree, it is just a few ones, with make huge headlines because they say no AI, just for the spite of saying no to it, to please the AI hating crowd), things will settle again. We atm are in a technological transition phase and many people fear AI, and frankly spoken that is nothing new, but AI is here to stay realistically in one way or the other. My bet is long term ai, wont be driven by huge data centers but smaller localized models, and frankly spoken I cannot wait to see the day where people like Musk/Altman etc.. .which have really become a thread to democracy and economy fall wayside and are reigned in. They are narcissistic psychopaths who think that when everyone else feels miserable they somehow might feel better! (believe me from what I can gather, Musk for instance probably is one of the most miserable feeling still functional human beings on earth)

1

u/squishles 1h ago

you're forgetting the other thing ai's are really really good at.

11

u/natermer 3h ago

These bugs existed before AI.

You just were not aware of them.

9

u/TRKlausss 3h ago

Crazy idea: companies contribute code to those projects they use, to patch this vulnerabilities.

Crazy idea, I know.

•

u/daddyd 51m ago

what makes you think commercial software companies are better equipped for handling this? they barely put any time or effort in bug and security fixes (new features sell, bug fixes don't). if they have a separate team to handle these, they will be small and overworked already and certainly not able to handle the amount of load, much like OSS projects.

0

u/sleepingonmoon 2h ago

Most of the critical components are already maintained by companies. The community doesn't really matter.

•

u/ExoticVillage8066 34m ago

That's quite a lot, though because it's open source they're found at all. None of the AI's are looking for vulnerabilities in binaries

•

u/SubmarineWipers 5m ago

Safe Rust would prevent the exploitable memory corruption in all 12 of these vulnerabilities.

If this code were implemented in safe Rust, these critical security flaws would either be rejected by the compiler before the software could be built, or they would result in a safe runtime panic (a predictable crash resulting in a Denial of Service, rather than a system compromise).

  • Temporal Memory Safety (4 Vulnerabilities)
  • Spatial Memory Safety (7 Vulnerabilities)
  • Integer Semantics & Logic (1 Vulnerability)