-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 19 Feb 2025 14:42:13 +0100 Source: xorg-server Binary: xorg-server-source xserver-common Architecture: all Version: 2:21.1.7-3+deb12u9 Distribution: bookworm-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Salvatore Bonaccorso Description: xorg-server-source - Xorg X server - source files xserver-common - common files used by various X servers Changes: xorg-server (2:21.1.7-3+deb12u9) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Cursor: Refuse to free the root cursor (CVE-2025-26594) * dix: keep a ref to the rootCursor (CVE-2025-26594) * xkb: Fix buffer overflow in XkbVModMaskText() (CVE-2025-26595) * xkb: Fix computation of XkbSizeKeySyms (CVE-2025-26596) * xkb: Fix buffer overflow in XkbChangeTypesOfKey() (CVE-2025-26597) * Xi: Fix barrier device search (CVE-2025-26598) * composite: Handle failure to redirect in compRedirectWindow() (CVE-2025-26599) * composite: initialize border clip even when pixmap alloc fails (CVE-2025-26599) * dix: Dequeue pending events on frozen device on removal (CVE-2025-26600) * sync: Do not let sync objects uninitialized (CVE-2025-26601) * sync: Check values before applying changes (CVE-2025-26601) * sync: Do not fail SyncAddTriggerToSyncObject() (CVE-2025-26601) * sync: Apply changes last in SyncChangeAlarmAttributes() (CVE-2025-26601) Checksums-Sha1: cae3edec0f4e427e19c1af9c22f9c146bf393944 7398268 xorg-server-source_21.1.7-3+deb12u9_all.deb c7c2ab7c3681397bbb8540857b6c3cde8819cb84 11575 xorg-server_21.1.7-3+deb12u9_all-buildd.buildinfo e66a857a21f508cf1853f6b60a711d7211433e96 2383064 xserver-common_21.1.7-3+deb12u9_all.deb Checksums-Sha256: fb9ff888dfed05ec596d1611bd4afb4cd511b3a57bb3d6277d451ea7701d0574 7398268 xorg-server-source_21.1.7-3+deb12u9_all.deb 6bd5e918c17839fef2408f0557c68f144cc6730bcf94930a1e06b268c4464516 11575 xorg-server_21.1.7-3+deb12u9_all-buildd.buildinfo e100a210bfe2e865f5edcd947dfabf894f7566461f6a0f0e7cd74a0e11fd05f3 2383064 xserver-common_21.1.7-3+deb12u9_all.deb Files: e57be19fc4e4063669264e367e6ec4b5 7398268 x11 optional xorg-server-source_21.1.7-3+deb12u9_all.deb 6ddffa3a6ab3a5975a859f6a818985f6 11575 x11 optional xorg-server_21.1.7-3+deb12u9_all-buildd.buildinfo 7a6a833ba71bb4a217bc9053c6bb37e8 2383064 x11 optional xserver-common_21.1.7-3+deb12u9_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEQsM0t1ygJv2xcx3e4cagXJhOTXsFAme2LwIACgkQ4cagXJhO TXuF6A/7BTzbSxPLY23Fz0EII33PouiE/MviDJFtR5egV128F25kFLf0KELUHNg+ i0tuzkp26ubq0ZNgZz417l3iiEPnH6DcqJBmfFGNp6DHd9Cf9ENn5tIR8EjUggAZ 6oJsJ9uHiGqLbkl0mxFSg4OBmweaEFV5R9NOfeP2OhkiMduwSOp6VQuOr/9OtK3B rrSJajrKBRHsnQeuDQrSJfEu/CXXdRtqxm6pVozxrAXMVrYKuKah92f6vqBFULci haDt+b5oprAyeNAAhKnrjczKfsEmRAhh7NLJEK5hjUpPaTzrloauR9cnZFXFCP+d FdJzZOllm4g29pZtzHsNuLMP704AZRV2PUN8IV9YnlLICQ5sWwbkZ8wroSWxjuM1 ZjPiyrSiEUMeYFmm/H1eoU6SWJ71v+fAQfPzGczkkgzTxrhMcol+jtwuKH0jM6sE bEd2QV4uctspxPb2ogqt6jIOj+c7QSajiyCl2vt/S+JimNhzcuVPNoREitL2NFTL RViWOMGgN8r0cDt/+P+dhnzcIGpP4GL7suytR9xsmX7griz0e2ui0v7xK86JHBdy QSJpcHDWUWzpbbpMTk93a9LDP6QBAo6oJwssY8aHdoTmR2eMoPwt2/c1f3zA+nXw B1aXEmWEQsHC2bMX60LMTjkZyUWsunfKeK7hCScR1Wbw8gmHyWQ= =8zaK -----END PGP SIGNATURE-----