[ubuntu/oracular-updates] xwayland 2:24.1.2-1ubuntu0.4 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Tue Feb 25 17:30:43 UTC 2025
xwayland (2:24.1.2-1ubuntu0.4) oracular-security; urgency=medium
* SECURITY UPDATE: Use-after-free of the root cursor
- debian/patches/CVE-2025-26594-1.patch: refuse to free the root cursor
in dix/dispatch.c.
- debian/patches/CVE-2025-26594-2.patch: keep a ref to the rootCursor
in dix/main.c.
- CVE-2025-26594
* SECURITY UPDATE: Buffer overflow in XkbVModMaskText()
- debian/patches/CVE-2025-26595.patch: fix bounds check in
xkb/xkbtext.c.
- CVE-2025-26595
* SECURITY UPDATE: Heap overflow in XkbWriteKeySyms()
- debian/patches/CVE-2025-26596.patch: fix computation of
XkbSizeKeySyms in xkb/xkb.c.
- CVE-2025-26596
* SECURITY UPDATE: Buffer overflow in XkbChangeTypesOfKey()
- debian/patches/CVE-2025-26597.patch: also resize key actions in
xkb/XKBMisc.c.
- CVE-2025-26597
* SECURITY UPDATE: Out-of-bounds write in CreatePointerBarrierClient()
- debian/patches/CVE-2025-26598.patch: fix barrier device search in
Xi/xibarriers.c.
- CVE-2025-26598
* SECURITY UPDATE: Use of uninitialized pointer in compRedirectWindow()
- debian/patches/CVE-2025-26599-1.patch: handle failure to redirect in
composite/compalloc.c.
- debian/patches/CVE-2025-26599-2.patch: initialize border clip even
when pixmap alloc fails in composite/compalloc.c.
- CVE-2025-26599
* SECURITY UPDATE: Use-after-free in PlayReleasedEvents()
- debian/patches/CVE-2025-26600.patch: dequeue pending events on frozen
device on removal in dix/devices.c.
- CVE-2025-26600
* SECURITY UPDATE: Use-after-free in SyncInitTrigger()
- debian/patches/CVE-2025-26601-1.patch: do not let sync objects
uninitialized in Xext/sync.c.
- debian/patches/CVE-2025-26601-2.patch: check values before applying
changes in Xext/sync.c.
- debian/patches/CVE-2025-26601-3.patch: do not fail
SyncAddTriggerToSyncObject() in Xext/sync.c.
- debian/patches/CVE-2025-26601-4.patch: apply changes last in
SyncChangeAlarmAttributes() in Xext/sync.c.
- CVE-2025-26601
* Note: this package does _not_ contain the changes from
(2:24.1.2-1ubuntu0.3) in oracular-proposed.
Date: 2025-02-19 15:15:20.896903+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/xwayland/2:24.1.2-1ubuntu0.4
-------------- next part --------------
Sorry, changesfile not available.
More information about the oracular-changes
mailing list