UbuntuUpdates.org

Package "xwayland"

Name: xwayland

Description:

X server for running X clients under Wayland

Latest version: 2:22.1.1-1ubuntu0.14
Release: jammy (22.04)
Level: security
Repository: main
Homepage: https://www.x.org/

Links


Download "xwayland"


Other versions of "xwayland" in Jammy

Repository Area Version
base main 2:22.1.1-1
updates main 2:22.1.1-1ubuntu0.14

Changelog

Version: 2:22.1.1-1ubuntu0.9 2023-12-13 16:11:38 UTC

  xwayland (2:22.1.1-1ubuntu0.9) jammy-security; urgency=medium

  * SECURITY UPDATE: Out-of-bounds memory write in XKB button actions
    - debian/patches/CVE-2023-6377.patch: allocate enough XkbActions for
      our buttons in Xi/exevents.c, dix/devices.c.
    - CVE-2023-6377
  * SECURITY UPDATE: Out-of-bounds memory read in RRChangeOutputProperty
    and RRChangeProviderProperty
    - debian/patches/CVE-2023-6478.patch: avoid integer truncation in
      length check of ProcRRChange*Property in randr/rrproperty.c,
      randr/rrproviderproperty.c.
    - CVE-2023-6478

 -- Marc Deslauriers <email address hidden> Tue, 12 Dec 2023 20:32:35 -0500

Source diff to previous version
CVE-2023-6377 A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory
CVE-2023-6478 A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow wh

Version: 2:22.1.1-1ubuntu0.7 2023-10-25 19:14:22 UTC

  xwayland (2:22.1.1-1ubuntu0.7) jammy-security; urgency=medium

  * SECURITY UPDATE: OOB write in XIChangeDeviceProperty and
    RRChangeOutputProperty
    - debian/patches/CVE-2023-5367.patch: fix handling of PropModeAppend
      and PropModePrepend in Xi/xiproperty.c, randr/rrproperty.c.
    - CVE-2023-5367

 -- Marc Deslauriers <email address hidden> Mon, 16 Oct 2023 09:20:53 -0400

Source diff to previous version
CVE-2023-5367 X.Org server: OOB write in XIChangeDeviceProperty/RRChangeOutputProperty

Version: 2:22.1.1-1ubuntu0.6 2023-03-29 19:07:01 UTC

  xwayland (2:22.1.1-1ubuntu0.6) jammy-security; urgency=medium

  * SECURITY UPDATE: Overlay Window Use-After-Free
    - debian/patches/CVE-2023-1393.patch: fix use-after-free of the COW in
      composite/compwindow.c.
    - CVE-2023-1393

 -- Marc Deslauriers <email address hidden> Wed, 29 Mar 2023 09:05:35 -0400

Source diff to previous version

Version: 2:22.1.1-1ubuntu0.5 2023-02-08 19:06:58 UTC

  xwayland (2:22.1.1-1ubuntu0.5) jammy-security; urgency=medium

  * SECURITY UPDATE: DeepCopyPointerClasses use-after-free
    - debian/patches/CVE-2023-0494.patch: fix potential use-after-free in
      Xi/exevents.c.
    - CVE-2023-0494

 -- Marc Deslauriers <email address hidden> Tue, 07 Feb 2023 08:06:17 -0500

Source diff to previous version
CVE-2023-0494 Xi: fix potential use-after-free in DeepCopyPointerClasses

Version: 2:22.1.1-1ubuntu0.4 2022-12-14 14:06:31 UTC

  xwayland (2:22.1.1-1ubuntu0.4) jammy-security; urgency=medium

  * SECURITY UPDATE: XTestSwapFakeInput stack overflow
    - debian/patches/CVE-2022-46340.patch: disallow GenericEvents in
      XTestSwapFakeInput in Xext/xtest.c.
    - CVE-2022-46340
  * SECURITY UPDATE: XIPassiveUngrabDevice out-of-bounds access
    - debian/patches/CVE-2022-46341.patch: disallow passive grabs with a
      detail > 255 in Xi/xipassivegrab.c.
    - CVE-2022-46341
  * SECURITY UPDATE: XvdiSelectVideoNotify use-after-free
    - debian/patches/CVE-2022-46342.patch: free the XvRTVideoNotify when
      turning off from the same client in Xext/xvmain.c.
    - CVE-2022-46342
  * SECURITY UPDATE: ScreenSaverSetAttributes use-after-free
    - debian/patches/CVE-2022-46343.patch: free the screen saver resource
      when replacing it in Xext/saver.c.
    - CVE-2022-46343
  * SECURITY UPDATE: XIChangeProperty out-of-bounds access
    - debian/patches/CVE-2022-46344-1.patch: return an error from XI
      property changes if verification failed in Xi/xiproperty.c.
    - debian/patches/CVE-2022-46344-2.patch: avoid integer truncation in
      length check of ProcXIChangeProperty in Xi/xiproperty.c.
    - CVE-2022-46344
  * SECURITY UPDATE: XkbGetKbdByName use-after-free
    - debian/patches/CVE-2022-4283.patch: reset the radio_groups pointer to
      NULL after freeing it in xkb/xkbUtils.c.
    - CVE-2022-4283

 -- Marc Deslauriers <email address hidden> Wed, 07 Dec 2022 09:12:14 -0500

CVE-2022-46340 Xtest: disallow GenericEvents in XTestSwapFakeInput
CVE-2022-46341 Xi: disallow passive grabs with a detail > 255
CVE-2022-46342 Xext: free the XvRTVideoNotify when turning off from the same client
CVE-2022-46343 Xext: free the screen saver resource when replacing it
CVE-2022-46344 Xi: avoid integer truncation in length check of ProcXIChangeProperty
CVE-2022-4283 xkb: reset the radio_groups pointer to NULL after freeing it



About   -   Send Feedback to @ubuntu_updates