kumquat-buildroot/package/x11r7
Peter Korsgaard 0595f7c933 package/x11r7/xserver_xorg-server: security bump to version 21.1.10
Fixes the following security issues:

1) CVE-2023-6377: X.Org server: Out-of-bounds memory write in XKB button actions

A device has XKB button actions for each button on the device.  When a
logical device switch happens (e.g.  moving from a touchpad to a mouse), the
server re-calculates the information available on the respective master
device (typically the Virtual Core Pointer).  This re-calculation only
allocated enough memory for a single XKB action rather instead of enough for
the newly active physical device's number of button.  As a result, querying
or changing the XKB button actions results in out-of-bounds memory reads and
writes.

This may lead to local privilege escalation if the server is run as root or
remote code execution (e.g. x11 over ssh).

2) CVE-2023-6478: X.Org server: Out-of-bounds memory read in
RRChangeOutputProperty and RRChangeProviderProperty

This fixes an OOB read and the resulting information disclosure.

Length calculation for the request was clipped to a 32-bit integer.  With
the correct stuff->nUnits value the expected request size was truncated,
passing the REQUEST_FIXED_SIZE check.

The server then proceeded with reading at least stuff->nUnits bytes
(depending on stuff->format) from the request and stuffing whatever it finds
into the property.  In the process it would also allocate at least
stuff->nUnits bytes, i.e.  4GB.

See also CVE-2022-46344 where this issue was fixed for other requests.

For more details, see the advisory:
https://lists.x.org/archives/xorg-announce/2023-December/003435.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 9b62f5905e)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2024-01-10 21:03:02 +01:00
..
libxcb
mcookie
xapp_appres
xapp_bdftopcf
xapp_beforelight
xapp_bitmap
xapp_editres
xapp_fonttosfnt
xapp_fslsfonts
xapp_fstobdf
xapp_iceauth
xapp_ico
xapp_listres
xapp_luit
xapp_mkfontscale
xapp_oclock
xapp_rgb
xapp_rstart
xapp_scripts
xapp_sessreg
xapp_setxkbmap
xapp_showfont
xapp_smproxy
xapp_twm
xapp_viewres
xapp_x11perf
xapp_xauth
xapp_xbacklight
xapp_xbiff
xapp_xcalc
xapp_xclipboard
xapp_xclock
xapp_xcmsdb
xapp_xcompmgr
xapp_xconsole
xapp_xcursorgen
xapp_xdbedizzy
xapp_xditview
xapp_xdm
xapp_xdpyinfo
xapp_xdriinfo
xapp_xedit
xapp_xev
xapp_xeyes
xapp_xf86dga
xapp_xfd
xapp_xfindproxy
xapp_xfontsel
xapp_xfs
xapp_xfsinfo
xapp_xgamma
xapp_xgc
xapp_xhost
xapp_xinit
xapp_xinput
xapp_xinput-calibrator
xapp_xkbcomp
xapp_xkbevd
xapp_xkbprint
xapp_xkbutils
xapp_xkill
xapp_xload
xapp_xlogo
xapp_xlsatoms
xapp_xlsclients
xapp_xlsfonts
xapp_xmag
xapp_xman
xapp_xmessage
xapp_xmh
xapp_xmodmap
xapp_xmore
xapp_xpr
xapp_xprop
xapp_xrandr
xapp_xrdb
xapp_xrefresh
xapp_xset
xapp_xsetmode
xapp_xsetpointer
xapp_xsetroot
xapp_xsm
xapp_xstdcmap
xapp_xvidtune
xapp_xvinfo
xapp_xwd
xapp_xwininfo
xapp_xwud
xcb-proto
xcb-util
xcb-util-cursor
xcb-util-image
xcb-util-keysyms
xcb-util-renderutil
xcb-util-wm
xcursor-transparent-theme
xdata_xbitmaps
xdata_xcursor-themes
xdriver_xf86-input-evdev
xdriver_xf86-input-joystick
xdriver_xf86-input-libinput
xdriver_xf86-input-mouse
xdriver_xf86-input-synaptics
xdriver_xf86-input-tslib
xdriver_xf86-input-vmmouse
xdriver_xf86-video-amdgpu
xdriver_xf86-video-ark
xdriver_xf86-video-ast
xdriver_xf86-video-ati
xdriver_xf86-video-cirrus
xdriver_xf86-video-dummy
xdriver_xf86-video-fbdev
xdriver_xf86-video-fbturbo
xdriver_xf86-video-geode
xdriver_xf86-video-i128
xdriver_xf86-video-imx
xdriver_xf86-video-intel
xdriver_xf86-video-mach64
xdriver_xf86-video-mga
xdriver_xf86-video-neomagic
xdriver_xf86-video-nouveau
xdriver_xf86-video-nv
xdriver_xf86-video-openchrome
xdriver_xf86-video-qxl
xdriver_xf86-video-r128
xdriver_xf86-video-savage
xdriver_xf86-video-siliconmotion
xdriver_xf86-video-sis
xdriver_xf86-video-tdfx
xdriver_xf86-video-trident
xdriver_xf86-video-vesa
xdriver_xf86-video-vmware
xdriver_xf86-video-voodoo
xfont_encodings
xfont_font-adobe-75dpi
xfont_font-adobe-100dpi
xfont_font-adobe-utopia-75dpi
xfont_font-adobe-utopia-100dpi
xfont_font-adobe-utopia-type1
xfont_font-alias
xfont_font-arabic-misc
xfont_font-bh-75dpi
xfont_font-bh-100dpi
xfont_font-bh-lucidatypewriter-75dpi
xfont_font-bh-lucidatypewriter-100dpi
xfont_font-bh-ttf
xfont_font-bh-type1
xfont_font-bitstream-75dpi
xfont_font-bitstream-100dpi
xfont_font-bitstream-type1
xfont_font-cronyx-cyrillic
xfont_font-cursor-misc
xfont_font-daewoo-misc
xfont_font-dec-misc
xfont_font-ibm-type1
xfont_font-isas-misc
xfont_font-jis-misc
xfont_font-micro-misc
xfont_font-misc-cyrillic
xfont_font-misc-ethiopic
xfont_font-misc-meltho
xfont_font-misc-misc
xfont_font-mutt-misc
xfont_font-schumacher-misc
xfont_font-screen-cyrillic
xfont_font-sony-misc
xfont_font-sun-misc
xfont_font-util
xfont_font-winitzki-cyrillic
xfont_font-xfree86-type1
xkeyboard-config
xlib_libdmx
xlib_libfontenc
xlib_libFS
xlib_libICE
xlib_libSM
xlib_libX11
xlib_libXau
xlib_libXaw
xlib_libXcomposite
xlib_libXcursor
xlib_libxcvt
xlib_libXdamage
xlib_libXdmcp
xlib_libXext
xlib_libXfixes
xlib_libXfont
xlib_libXfont2
xlib_libXft
xlib_libXi
xlib_libXinerama
xlib_libxkbfile
xlib_libXmu
xlib_libXpm
xlib_libXpresent
xlib_libXrandr
xlib_libXrender
xlib_libXres
xlib_libXScrnSaver
xlib_libxshmfence
xlib_libXt
xlib_libXtst
xlib_libXv
xlib_libXvMC
xlib_libXxf86dga
xlib_libXxf86vm
xlib_xtrans
xorgproto
xserver_xorg-server package/x11r7/xserver_xorg-server: security bump to version 21.1.10 2024-01-10 21:03:02 +01:00
xutil_makedepend
xwayland package/x11r7/xwayland: security bump to 23.2.3 2024-01-10 11:19:01 +01:00
Config.in
x11r7.mk