]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
xserver-xorg: Fix Multiple CVEs
authorHitendra Prajapati <hprajapati@mvista.com>
Tue, 24 Jan 2023 04:44:48 +0000 (10:14 +0530)
committerSteve Sakoman <steve@sakoman.com>
Sat, 4 Feb 2023 14:34:20 +0000 (04:34 -1000)
commitdcc597d52a579fca44581ebd81b4a15fa56456fe
tree98ef77074e7892c8df6fb33a6ce7451aa93317fa
parenta626228a4be4c52c9d3f43eb1756c1defc22a5e4
xserver-xorg: Fix Multiple CVEs

CVE-2022-4283: xkb: reset the radio_groups pointer to NULL after freeing it
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/ccdd431cd8f1cabae9d744f0514b6533c438908c

CVE-2022-46340: Xtest: disallow GenericEvents in XTestSwapFakeInput
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/b320ca0ffe4c0c872eeb3a93d9bde21f765c7c63

CVE-2022-46341: Xi: disallow passive grabs with a detail > 255
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/51eb63b0ee1509c6c6b8922b0e4aa037faa6f78b

CVE-2022-46342: Xext: free the XvRTVideoNotify when turning off from the same client
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/b79f32b57cc0c1186b2899bce7cf89f7b325161b

CVE-2022-46343: Xext: free the screen saver resource when replacing it
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/842ca3ccef100ce010d1d8f5f6d6cc1915055900

CVE-2022-46344: Xi: avoid integer truncation in length check of ProcXIChangeProperty
Upstream-Status: Backport from https://gitlab.freedesktop.org/xorg/xserver/-/commit/8f454b793e1f13c99872c15f0eed1d7f3b823fe8

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-graphics/xorg-xserver/xserver-xorg/CVE-2022-4283.patch [new file with mode: 0644]
meta/recipes-graphics/xorg-xserver/xserver-xorg/CVE-2022-46340.patch [new file with mode: 0644]
meta/recipes-graphics/xorg-xserver/xserver-xorg/CVE-2022-46341.patch [new file with mode: 0644]
meta/recipes-graphics/xorg-xserver/xserver-xorg/CVE-2022-46342.patch [new file with mode: 0644]
meta/recipes-graphics/xorg-xserver/xserver-xorg/CVE-2022-46343.patch [new file with mode: 0644]
meta/recipes-graphics/xorg-xserver/xserver-xorg/CVE-2022-46344.patch [new file with mode: 0644]
meta/recipes-graphics/xorg-xserver/xserver-xorg_1.20.14.bb