{"schema_version": "1.7.0", "id": "RLSA-2023:2786", "modified": "2026-06-27T00:06:10.316736Z", "published": "2026-06-27T00:01:04.193077Z", "upstream": ["CVE-2021-3782"], "summary": "Moderate: wayland security, bug fix, and enhancement update", "details": "Wayland is a protocol for a compositor to talk to its clients, as well as a C library implementation of that protocol. The compositor can be a standalone display server running on Linux kernel modesetting and evdev input devices, an X application, or a wayland client itself. The clients can be traditional applications, X servers (rootless or fullscreen) or other display servers.\n\nThe following packages have been upgraded to a later upstream version: wayland (1.21.0). (BZ#2137625)\n\nSecurity Fix(es):\n\n* wayland: libwayland-server wl_shm reference-count overflow (CVE-2021-3782)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.8 Release Notes linked from the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:8", "name": "wayland", "purl": "pkg:rpm/rocky-linux/wayland?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.21.0-1.el8"}], "database_specific": {"yum_repository": "AppStream"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2023:2786"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2002627"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}