Opened 4 weeks ago

Closed 4 weeks ago

Last modified 4 weeks ago

#19650 closed enhancement (fixed)

xorg-server-21.1.13

Reported by: Douglas R. Reno Owned by: Bruce Dubbs
Priority: normal Milestone: 12.2
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version

Fixes a regression introduced by the recent security update. When this goes in, the version number for the advisory for Xorg-Server and XWayland will need to be updated.

The fix we provided for CVE-2024-31083 introduced a double-free in some
circumstances, which led to X server crashes.

This has been fixed now in xorg-server-21.1.13 and xwayland-23.2.6.

For those applying patches instead of upgrades, see
https://gitlab.freedesktop.org/xorg/xserver/-/commit/337d8d48b618d4fc0168a7b978be4c3447650b04

         -Alan Coopersmith-              alan.coopersmith@oracle.com
           X.Org Security Response Team - xorg-security@lists.x.org

The release announcement also has:

Matt Turner (1):
      xserver 21.1.13

Olivier Fourdan (1):
      render: Avoid possible double-free in ProcRenderAddGlyphs()

Willem Jan Palenstijn (1):
      mi: fix rounding issues around zero in miPointerSetPosition

git tag: xorg-server-21.1.13

Change History (3)

comment:1 by Bruce Dubbs, 4 weeks ago

Owner: changed from blfs-book to Bruce Dubbs
Status: newassigned

comment:2 by Bruce Dubbs, 4 weeks ago

Resolution: fixed
Status: assignedclosed

Fixed at commits

6efb7af351 Update to xwayland-23.2.6.
d8b200ef4a Update to xorg-server-21.1.13.

comment:3 by Douglas R. Reno, 4 weeks ago

Security advisories updated to point to new versions

Note: See TracTickets for help on using tickets.