xkbcomp-1.5.0 (Xorg App)
New minor version
Release notes:
This releases contains the fixes for the issues reported in today's security
advisory: https://lists.x.org/archives/xorg-announce/2025-December/003644.html
* CVE-2018-15863
* CVE-2018-15861
* CVE-2018-15859
* CVE-2018-15853
Note that the year is not a typo, these CVEs have been reported previously for
libxkbcommon but the same code exists in xkbcomp and required the same fixes.
As a new feature in this version: xkbcomp now supports the meson build system
in addition to autotools. autotools support may be removed in a future version.
The full git shortlog for this release is below:
Alan Coopersmith (6):
Assume target platforms have strcasecmp, strncasecmp, & strdup now
Use _stricmp()/_strnicmp() instead of strcasecmp()/strncasecmp() on Windows
Accept --help & --version as aliases to -help & -version
Improve man page formatting
man page: fix warnings from `mandoc -T lint`
Make sure config.h is included before any system headers
Daniel Stone (3):
xkbcomp: Don't crash on no-op modmask expressions
xkbcomp: Don't falsely promise from ExprResolveLhs
Fail expression lookup on invalid atoms
Matthieu Herrb (1):
Symbols: resize the syms array when removing NoSymbol
Peter Hutterer (1):
xkbcomp 1.5.0
Pierre Le Marre (12):
Symbols: Fix out-of-bounds actions in MergeKeyGroups
types: Fix warning for multiple map occurrences
types: Fix typo in warning
symbols: Fix NULL pointer dereference in MergeKeyGroups
Add support for meson build
Compare autotools and meson builds
build: Fix meson linking order
Fix various undefined behaviors
parser: Fix whitespaces
parser: Fix multiple keysyms per level parsing
parser: Refactor multiple keysyms per level and add warning
parser: Parse but discard multiple actions per level
Ran Benita (1):
xkbcomp: fix stack overflow when evaluating boolean negation
... and the security advisory (note, 2018 is *not* a typo...)
======================================================================
X.Org Security Advisory: Wed 3, 2025
Issues in xkbcomp prior to version 1.5.0
======================================================================
Multiple issues have been found in xkbcomp that have been previously
been published as CVEs in libxbkcommon. libxkbcommon is (to some degree)
a fork of xkbcomp and some of the code base is identical. These CVEs
were published earlier as:
- CVE-2018-15853: Endless recursion in xkbcomp/expr.c resulting in a
crash
https://gitlab.freedesktop.org/xorg/app/xkbcomp/-/commit/da8367645
- CVE-2018-15859: NULL pointer dereference when parsing invalid atoms in
ExprResolveLhs resulting in a crash
https://gitlab.freedesktop.org/xorg/app/xkbcomp/-/commit/895e080b2
- CVE-2018-15861: NULL pointer dereference in ExprResolveLhs resulting
in a crash
https://gitlab.freedesktop.org/xorg/app/xkbcomp/-/commit/c34263540
- CVE-2018-15863: NULL pointer dereference in ResolveStateAndPredicate
resulting in a crash
https://gitlab.freedesktop.org/xorg/app/xkbcomp/-/commit/fa10dbc2c
These four issues also affect xkbcomp. As the issues have been
effectively public for a while, there is no embargo. xkbcomp 1.5.0 is
available now and contains these fixes.
Change History
(8)
| Priority: |
normal → elevated
|
| Owner: |
changed from blfs-book to Douglas R. Reno
|
| Status: |
new → assigned
|
| Owner: |
changed from Douglas R. Reno to Bruce Dubbs
|
| Status: |
assigned → new
|
| Owner: |
changed from Bruce Dubbs to Douglas R. Reno
|
| Status: |
assigned → new
|
| Resolution: |
→ fixed
|
| Status: |
assigned → closed
|
Fixed at commits
Leaving open for security advisories and reassigning.