]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
xwayland: fix CVE-2025-49175
authorArchana Polampalli <archana.polampalli@windriver.com>
Thu, 3 Jul 2025 10:23:49 +0000 (15:53 +0530)
committerSteve Sakoman <steve@sakoman.com>
Thu, 3 Jul 2025 20:10:12 +0000 (13:10 -0700)
commit2c8e82f860792e7fb99c78c512be57ce74774a34
tree5848af3af99c3e080c5a97b0343e2dec34251886
parent574146765ea3f9b36532abf4ebc8bd2976396f0b
xwayland: fix CVE-2025-49175

A flaw was found in the X Rendering extension's handling of animated cursors.
If a client provides no cursors, the server assumes at least one is present,
leading to an out-of-bounds read and potential crash.

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-graphics/xwayland/xwayland/CVE-2025-49175.patch [new file with mode: 0644]
meta/recipes-graphics/xwayland/xwayland_22.1.8.bb