#22323 closed enhancement (fixed)
xorg-server-21.1.20
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (6)
comment:1 by , 11 months ago
| Priority: | normal → elevated |
|---|
- CVE-2025-62229: Use-after-free in XPresentNotify structures creation
- CVE-2025-62230: Use-after-free in Xkb client resource removal
- CVE-2025-62231: Value overflow in Xkb extension XkbSetCompatMap()
comment:2 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 11 months ago
xserver 21.1.20
- Quick release to fix the missing files in 21.1.19.
xserver 21.1.19
- xkb: Prevent overflow in XkbSetCompatMap()
The XkbCompatMap structure stores its "num_si" and "size_si" fields using an unsigned short.
However, the function _XkbSetCompatMap() will store the sum of the input data "firstSI" and "nSI" in both XkbCompatMap's "num_si" and "size_si" without first checking if the sum overflows the maximum unsigned short value, leading to a possible overflow.
To avoid the issue, check whether the sum does not exceed the maximum unsigned short value, or return a "BadValue" error otherwise.
CVE-2025-62231, ZDI-CAN-27560
- xkb: Free the XKB resource when freeing XkbInterest
CVE-2025-62230, ZDI-CAN-27545
- xkb: Make the RT_XKBCLIENT resource private
CVE-2025-62230, ZDI-CAN-27545
- present: Fix use-after-free in present_create_notifies()
CVE-2025-62229, ZDI-CAN-27238
- dix: avoid memory leak in ProcListProperties()
- dix: handle allocation failure in ChangeWindowDeviceCursor()
- dix: assert that size of buffers to swap is a multiple of the swap size
- dix: avoid null dereference if wOtherInputMasks() returns NULL
- dix: handle allocation failure in DeviceFocusEvent()
- Xi: handle allocation failure in add_master_func()
- Xi: handle allocation failure in ProcXListInputDevices()
- Xi: handle allocation failure in ProcXGetDeviceDontPropagateList()
- Xi: set value for led_values in CopySwapKbdFeedback()
- Xi: avoid null dereference if wOtherInputMasks() returns NULL
- Xext/xtest: avoid null dereference in ProcXTestFakeInput()
- Xext/xselinux: avoid memory leak in SELinuxAtomToSID()
- Xext/xselinux: add fast path to ProcSELinuxListSelections()
- Xext/xres: avoid null dereference in ProcXResQueryClients()
- Xext/vidmode: avoid null dereference if VidModeCreateMode() allocation fails
- Xext/sync: Avoid dereference of invalid pointer if malloc() failed
- Xext/sync: avoid null dereference in init_system_idle_counter()
- Xext/sync: avoid null dereference if SysCounterGetPrivate() returns NULL
- Xext/shm: avoid null dereference in ShmInitScreenPriv()
- xfree86: Fix -Wdiscarded-qualifiers warnings in SPARC Sbus probe code
- xfree86: add missing headers to build sun_init.c on Solaris/SPARC
- xfree86: fix meson build on 64-bit Solaris/SPARC systems
Other numerous bug fixes - See the ChangeLog file.
comment:4 by , 11 months ago
Fixed at commits
0eea9e8e39 Update to xwayland-24.1.9. new bb9862f0c9 Update to xorg-server-21.1.20.
Leaving open for now for security advisories.
comment:5 by , 11 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
SA-12.4-028 issued.
Also brought up a reminder about the dangers of leaving these unpatched on systems with SSH X Forwarding enabled or TigerVNC running.
