Revisions of xwayland

Marcus Rueckert's avatar Marcus Rueckert (darix) committed (revision 6)
CRD: 2023-03-29 12:00 UTC

- U_xserver-composite-Fix-use-after-free-of-the-COW.patch
  * overlay window use-after-free (CVE-2023-1393, ZDI-CAN-19866,
    bsc#1209543)
Marco Strigl's avatar Marco Strigl (mstrigl) committed (revision 5)
- U_Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch
  * fixes regression introduced with security update for
    CVE-2022-46340 (bsc#1205874)
Marco Strigl's avatar Marco Strigl (mstrigl) committed (revision 4)
Not to be checked in before CRD 2023-02-07

- U_Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch
  * DeepCopyPointerClasses use-after-free (CVE-2023-0494, 
    ZDI-CAN-19596, bsc#1207783)
Marcus Rueckert's avatar Marcus Rueckert (darix) committed (revision 3)
CRD 2022-12-14. Please don't check in before!

- U_0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch
  * XkbGetKbdByName use-after-free (ZDI-CAN-19530, CVE-2022-4283,
    bsc#1206017)

- U_0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch
  * Server XTestSwapFakeInput stack overflow (ZDI-CAN 19265,
    CVE-2022-46340, bsc#1205874)
- U_0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch
  * Xi: return an error from XI property changes if verification
    failed (no ZDI-CAN id, no CVE id, bsc#1205875)
- U_0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch
  * Server XIChangeProperty out-of-bounds access (ZDI-CAN 19405,
    CVE-2022-46344, bsc#1205876)
- U_0004-Xi-disallow-passive-grabs-with-a-detail-255.patch
  * Server XIPassiveUngrabDevice out-of-bounds access (ZDI-CAN 19381,
    CVE-2022-46341, bsc#1205877)
- U_0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch
  * Server ScreenSaverSetAttributes use-after-free (ZDI-CAN 19404,
    CVE-2022-46343, bsc#1205878)
- U_0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch
  * Server XvdiSelectVideoNotify use-after-free (ZDI-CAN 19400,
    CVE-2022-46342, bsc#1205879)
Daniel Mach's avatar Daniel Mach (dmach) committed (revision 2)
Latest bugfix release; important for GNOME desktop
Daniel Mach's avatar Daniel Mach (dmach) committed (revision 1)
initialize package
Displaying all 6 revisions
openSUSE Build Service is sponsored by