Opened 11 months ago

Closed 11 months ago

Last modified 8 months ago

#22323 closed enhancement (fixed)

xorg-server-21.1.20

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by Xi Ruoyao, 11 months ago

Priority: normal → elevated
  • CVE-2025-62229: Use-after-free in XPresentNotify structures creation
  • CVE-2025-62230: Use-after-free in Xkb client resource removal
  • CVE-2025-62231: Value overflow in Xkb extension XkbSetCompatMap()

comment:2 by Bruce Dubbs, 11 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:3 by Bruce Dubbs, 11 months ago

xserver 21.1.20

  • Quick release to fix the missing files in 21.1.19.

xserver 21.1.19

  • xkb: Prevent overflow in XkbSetCompatMap()

The XkbCompatMap structure stores its "num_si" and "size_si" fields using an unsigned short.

However, the function _XkbSetCompatMap() will store the sum of the input data "firstSI" and "nSI" in both XkbCompatMap's "num_si" and "size_si" without first checking if the sum overflows the maximum unsigned short value, leading to a possible overflow.

To avoid the issue, check whether the sum does not exceed the maximum unsigned short value, or return a "BadValue" error otherwise.

CVE-2025-62231, ZDI-CAN-27560

  • xkb: Free the XKB resource when freeing XkbInterest

CVE-2025-62230, ZDI-CAN-27545

  • xkb: Make the RT_XKBCLIENT resource private

CVE-2025-62230, ZDI-CAN-27545

  • present: Fix use-after-free in present_create_notifies()

CVE-2025-62229, ZDI-CAN-27238

  • dix: avoid memory leak in ProcListProperties()
  • dix: handle allocation failure in ChangeWindowDeviceCursor()
  • dix: assert that size of buffers to swap is a multiple of the swap size
  • dix: avoid null dereference if wOtherInputMasks() returns NULL
  • dix: handle allocation failure in DeviceFocusEvent()
  • Xi: handle allocation failure in add_master_func()
  • Xi: handle allocation failure in ProcXListInputDevices()
  • Xi: handle allocation failure in ProcXGetDeviceDontPropagateList()
  • Xi: set value for led_values in CopySwapKbdFeedback()
  • Xi: avoid null dereference if wOtherInputMasks() returns NULL
  • Xext/xtest: avoid null dereference in ProcXTestFakeInput()
  • Xext/xselinux: avoid memory leak in SELinuxAtomToSID()
  • Xext/xselinux: add fast path to ProcSELinuxListSelections()
  • Xext/xres: avoid null dereference in ProcXResQueryClients()
  • Xext/vidmode: avoid null dereference if VidModeCreateMode() allocation fails
  • Xext/sync: Avoid dereference of invalid pointer if malloc() failed
  • Xext/sync: avoid null dereference in init_system_idle_counter()
  • Xext/sync: avoid null dereference if SysCounterGetPrivate() returns NULL
  • Xext/shm: avoid null dereference in ShmInitScreenPriv()
  • xfree86: Fix -Wdiscarded-qualifiers warnings in SPARC Sbus probe code
  • xfree86: add missing headers to build sun_init.c on Solaris/SPARC
  • xfree86: fix meson build on 64-bit Solaris/SPARC systems

Other numerous bug fixes - See the ChangeLog file.

comment:4 by Bruce Dubbs, 11 months ago

Fixed at commits

0eea9e8e39 Update to xwayland-24.1.9.
new bb9862f0c9 Update to xorg-server-21.1.20.

Leaving open for now for security advisories.

comment:5 by Douglas R. Reno, 11 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-028 issued.

Also brought up a reminder about the dangers of leaving these unpatched on systems with SSH X Forwarding enabled or TigerVNC running.

comment:6 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.