-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 19 Feb 2025 14:42:13 +0100 Source: xorg-server Binary: xnest xnest-dbgsym xserver-xephyr xserver-xephyr-dbgsym xserver-xorg-core xserver-xorg-core-dbgsym xserver-xorg-core-udeb xserver-xorg-dev xserver-xorg-legacy xserver-xorg-legacy-dbgsym xvfb xvfb-dbgsym Architecture: mipsel Version: 2:21.1.7-3+deb12u9 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Salvatore Bonaccorso Description: xnest - Nested X server xserver-xephyr - nested X server xserver-xorg-core - Xorg X server - core server xserver-xorg-core-udeb - Xorg X server - core server (udeb) xserver-xorg-dev - Xorg X server - development files xserver-xorg-legacy - setuid root Xorg server wrapper xvfb - Virtual Framebuffer 'fake' X server Changes: xorg-server (2:21.1.7-3+deb12u9) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Cursor: Refuse to free the root cursor (CVE-2025-26594) * dix: keep a ref to the rootCursor (CVE-2025-26594) * xkb: Fix buffer overflow in XkbVModMaskText() (CVE-2025-26595) * xkb: Fix computation of XkbSizeKeySyms (CVE-2025-26596) * xkb: Fix buffer overflow in XkbChangeTypesOfKey() (CVE-2025-26597) * Xi: Fix barrier device search (CVE-2025-26598) * composite: Handle failure to redirect in compRedirectWindow() (CVE-2025-26599) * composite: initialize border clip even when pixmap alloc fails (CVE-2025-26599) * dix: Dequeue pending events on frozen device on removal (CVE-2025-26600) * sync: Do not let sync objects uninitialized (CVE-2025-26601) * sync: Check values before applying changes (CVE-2025-26601) * sync: Do not fail SyncAddTriggerToSyncObject() (CVE-2025-26601) * sync: Apply changes last in SyncChangeAlarmAttributes() (CVE-2025-26601) Checksums-Sha1: d7be5d82e2c0ba107b6923ed893c257aaadf0da7 2684352 xnest-dbgsym_21.1.7-3+deb12u9_mipsel.deb 73556e6fc055e331586d8f4cb350098e8bdb6c12 2935104 xnest_21.1.7-3+deb12u9_mipsel.deb f78196ee2044bf3c3bf551e38e49379e6d8630af 14536 xorg-server_21.1.7-3+deb12u9_mipsel-buildd.buildinfo 2ea499827a157f88407978d05b02a70c489328fa 3954228 xserver-xephyr-dbgsym_21.1.7-3+deb12u9_mipsel.deb c75ff01b95f6927f5c346314df2bc2a2a7dd45ec 3178452 xserver-xephyr_21.1.7-3+deb12u9_mipsel.deb 6e4a22981e51b3e55244532f36e3c8017cf77355 5774896 xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_mipsel.deb 33b71bb5b3bc5717a8f3849418bd0b427ddf1c03 839344 xserver-xorg-core-udeb_21.1.7-3+deb12u9_mipsel.udeb e13c85ef1ca4814a71fb4e1dd904cf708d4ad786 3545604 xserver-xorg-core_21.1.7-3+deb12u9_mipsel.deb 547d1b8c5f92d3c88d6e41cdfec21629fbeb193a 2554504 xserver-xorg-dev_21.1.7-3+deb12u9_mipsel.deb 51db921026532711c2c1cf19ad7763c08b1eda28 9528 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_mipsel.deb d1ccede552837b968d7018fe56a9623b26a00767 2388552 xserver-xorg-legacy_21.1.7-3+deb12u9_mipsel.deb 35a77b9f9ebe514a6c6d836b308a1cc73afe0e8e 3272424 xvfb-dbgsym_21.1.7-3+deb12u9_mipsel.deb 0c647aac4ea4b7cff621391ed0d94816a6ffc4cf 3057212 xvfb_21.1.7-3+deb12u9_mipsel.deb Checksums-Sha256: 885d0188f2470d10fada8d8a9346f79ea66af3ed5e6df970a28db5e8ea04623b 2684352 xnest-dbgsym_21.1.7-3+deb12u9_mipsel.deb d536ff40edd431cd9ab5fcb57030a5993ef3282ef80ce30cc0225dc4f85d1922 2935104 xnest_21.1.7-3+deb12u9_mipsel.deb 64f4d0a3e147cd097d2731bf51a1e0cb60011dc4786bd7ab0c7a400af9a922c3 14536 xorg-server_21.1.7-3+deb12u9_mipsel-buildd.buildinfo a5f2eb7aadd04f06ce244e93641b9e27aa1b7014209262a35bda5868889fdc47 3954228 xserver-xephyr-dbgsym_21.1.7-3+deb12u9_mipsel.deb cecb62868c7052ebb42c6124b2fdd13ed0bc19f5b177435f6778a61119b0b0ed 3178452 xserver-xephyr_21.1.7-3+deb12u9_mipsel.deb a76423420dc37a47e1415565ab181780dad5006146c8f092d72d585cc56f7c6a 5774896 xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_mipsel.deb 321a65a16d2cc8f38e9b416a38b3e3d830fcb55ac03c7fd63aac34e13cf63099 839344 xserver-xorg-core-udeb_21.1.7-3+deb12u9_mipsel.udeb 27d41d48ef32fc980a1bd3291be047acd2300b00f5db4858aaac8b117e6798cf 3545604 xserver-xorg-core_21.1.7-3+deb12u9_mipsel.deb 8e3734fc31ecea72800b37111d941af69f0f40ae1d72fc3cf3394d0d3b93928d 2554504 xserver-xorg-dev_21.1.7-3+deb12u9_mipsel.deb afc31c617340eee7ed2ec779e81eb26367f118a8570efbd6a0cb184bd2a78d23 9528 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_mipsel.deb be9d80ee438bd3c049970c6a1f276e8d920c6c038c7b7507407e4b999632768b 2388552 xserver-xorg-legacy_21.1.7-3+deb12u9_mipsel.deb bd1d28a59e69d1902f74d4584c8f99973f9f4ff6c8db8948b81796d01720c2fb 3272424 xvfb-dbgsym_21.1.7-3+deb12u9_mipsel.deb 9ae35fa4036bfdaf6f5a5641c482cf4a80510794009485fd17a083bbfafb5769 3057212 xvfb_21.1.7-3+deb12u9_mipsel.deb Files: fdf7cae048e4021429ec0cb6ba6e0bd9 2684352 debug optional xnest-dbgsym_21.1.7-3+deb12u9_mipsel.deb 6f75ee5acfb83a8b829390e2150d7f95 2935104 x11 optional xnest_21.1.7-3+deb12u9_mipsel.deb c8f75d2b5696c2d645765c1717fa3665 14536 x11 optional xorg-server_21.1.7-3+deb12u9_mipsel-buildd.buildinfo 363d3c4135c57e3ffb781c5410ec5412 3954228 debug optional xserver-xephyr-dbgsym_21.1.7-3+deb12u9_mipsel.deb 6c80a09c8ea4f77fcffa7e8402141be0 3178452 x11 optional xserver-xephyr_21.1.7-3+deb12u9_mipsel.deb d8e3fe54f48319d1abd8f93877974e75 5774896 debug optional xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_mipsel.deb b4c07317f4f603983785860d355534e7 839344 debian-installer optional xserver-xorg-core-udeb_21.1.7-3+deb12u9_mipsel.udeb 0f3bb4f678f6f0531ef420102c9fd067 3545604 x11 optional xserver-xorg-core_21.1.7-3+deb12u9_mipsel.deb cd24d6eca2e0a0fc7324fe82c3f7d833 2554504 x11 optional xserver-xorg-dev_21.1.7-3+deb12u9_mipsel.deb c1a923ae9d19244650941b7e86319371 9528 debug optional xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_mipsel.deb 40333d25b270f211c7572231df72688a 2388552 x11 optional xserver-xorg-legacy_21.1.7-3+deb12u9_mipsel.deb 79980f9ea9412824b840128026b44f89 3272424 debug optional xvfb-dbgsym_21.1.7-3+deb12u9_mipsel.deb c26f62c57afeb2238139f804521f7218 3057212 x11 optional xvfb_21.1.7-3+deb12u9_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAme2MGcACgkQC2Vm2FYV KKAV9BAAuzUYNaFzBpS8tu2hn7bgkYQWDZSoYBAzjlMi7dYiPTPeBQSInR6URsws ueqEQG9U2bmOvlqmjjaEOzRLBOLD0FTpObRYqUstKnoihjGdJEBj7ksUrnoMuDU3 OXuQd7N0Nlych380dXVci/KhwRv+x3jGHkZzraDYagWKLdXjugOM9q2n7SbxrMhs CSS7bKsDD7QC2rZxRyikaM/1sxA0COjWIQVmieMscgyiHccKy69H12oyzkaXVx5P PT4D97fTR2LRyPERBoULLFjf/haKlNrYrooZJuEzzHNvLoGXvadxnjgJNKNhS8jU x5bP5okyyR83+f7x5CcYwWM9iF/8+wqyNOzRQlxFKymuHlighmP0KNCMxCNzpsuQ 8W87zUHormTPi13sg5G9JRslVGK7t/cfnlCFm0ZpZZUhYdhTnUZU+vX81vJU0FbC +BeKi8ZRYoS1Bzmz2L6hK+Z77mlLovIrlUb4S4rlWsyuX2IOvIa4NShqI6FQhIal e9s+tpv6oxWBU6GkAavJOOrXhFs5EtfgHqDiZWf8YY9Vt3zB+YQ2HEtJ4D1eywdf O4loxmCSolFaPrPoWUo0/kVF5FtjqX9dDAeF5IXKJD+WxOe4S9oUWcZDE6Gb0lYq cv8UZ9lGTqvrw3XT28HJKeA/aTX+8kGUjhFkuVZEJvhJ66c7pb4= =6NjB -----END PGP SIGNATURE-----