Opened 3 months ago

Closed 2 months ago

#23577 closed enhancement (fixed)

xorg-server-21.1.24

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

This release contains the fixes for the issues reported in today's
security advisory:
https://lists.x.org/archives/xorg-announce/2026-July/003716.html

  -  CVE-2026-55999: glamor Font Atlas Heap Buffer Overflow
  -  CVE-2026-56000: GLX contextTags Use-After-Free in CommonMakeCurrent()

As noted in the security advisory, CVE-2026-56000 seems to depend on a
commit not previously in a 21.1.x release (but is present in this
release). As far as we can tell, 21.1.23 and earlier are not vulnerable
to CVE-2026-56000.

On top of those we have few cleanup fixes backported to the 21.1 releases.

Doğukan Korkmaztürk (1):
      GLX: Free the tag of the old context later

Jeremy Huddleston Sequoia (2):
      xquartz/GL: silence OpenGL deprecation warnings
      xquartz/GL: advertise GLX_ARB_create_context and _profile

Mikhail Dmitrichenko (1):
      xkb: preserve buffer on realloc failure

Olivier Fourdan (4):
      dix: Silence a compiler warning in doListFontsAndAliases()
      dix: Silent static analyzer warning
      dix: Silence a compiler warning in doListFontsWithInfo()
      Xi: Check window attribute is valid in XIChangeCursor

Peter Hutterer (7):
      dix/colormap: fix out-of-bounds read in FindColorInRootCmap
      glx: fix duplicate tagInfo->vendor = NULL assignment
      glamor: fix an error path cleanup
      glx: free old context tag before allocating new one in CommonMakeCurrent
      fb/mi/glamor: reject glyphs with negative dimensions
      glamor: reject fonts with per-glyph metrics exceeding maxbounds
      xserver 21.1.24

git tag: xorg-server-21.1.24

Change History (4)

comment:1 by Joe Locash, 3 months ago

Priority: normal → elevated

comment:2 by Joe Locash, 3 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 3 months ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at f792d89233. Leaving open for SA.

comment:4 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-155 has been issued.

Note: See TracTickets for help on using tickets.