]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
xwayland: fix CVE-2025-49177
authorArchana Polampalli <archana.polampalli@windriver.com>
Wed, 2 Jul 2025 15:46:16 +0000 (21:16 +0530)
committerSteve Sakoman <steve@sakoman.com>
Thu, 3 Jul 2025 16:04:44 +0000 (09:04 -0700)
commit0b2afd59ce8c35083c1cb3596a2f7d4eaa7bd1c8
tree473427f39891dbd88f5918a6e6c77b2481fa6350
parent0a2c5179e1f08ccd0fcaccb6f95c892ebafac8a8
xwayland: fix CVE-2025-49177

A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler
does not validate the request length, allowing a client to read unintended memory
from previous requests

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-graphics/xwayland/xwayland/CVE-2025-49177.patch [new file with mode: 0644]
meta/recipes-graphics/xwayland/xwayland_23.2.5.bb