-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 19 Feb 2025 14:42:13 +0100 Source: xorg-server Binary: xnest xnest-dbgsym xserver-xephyr xserver-xephyr-dbgsym xserver-xorg-core xserver-xorg-core-dbgsym xserver-xorg-core-udeb xserver-xorg-dev xserver-xorg-legacy xserver-xorg-legacy-dbgsym xvfb xvfb-dbgsym Architecture: ppc64el Version: 2:21.1.7-3+deb12u9 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Salvatore Bonaccorso Description: xnest - Nested X server xserver-xephyr - nested X server xserver-xorg-core - Xorg X server - core server xserver-xorg-core-udeb - Xorg X server - core server (udeb) xserver-xorg-dev - Xorg X server - development files xserver-xorg-legacy - setuid root Xorg server wrapper xvfb - Virtual Framebuffer 'fake' X server Changes: xorg-server (2:21.1.7-3+deb12u9) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Cursor: Refuse to free the root cursor (CVE-2025-26594) * dix: keep a ref to the rootCursor (CVE-2025-26594) * xkb: Fix buffer overflow in XkbVModMaskText() (CVE-2025-26595) * xkb: Fix computation of XkbSizeKeySyms (CVE-2025-26596) * xkb: Fix buffer overflow in XkbChangeTypesOfKey() (CVE-2025-26597) * Xi: Fix barrier device search (CVE-2025-26598) * composite: Handle failure to redirect in compRedirectWindow() (CVE-2025-26599) * composite: initialize border clip even when pixmap alloc fails (CVE-2025-26599) * dix: Dequeue pending events on frozen device on removal (CVE-2025-26600) * sync: Do not let sync objects uninitialized (CVE-2025-26601) * sync: Check values before applying changes (CVE-2025-26601) * sync: Do not fail SyncAddTriggerToSyncObject() (CVE-2025-26601) * sync: Apply changes last in SyncChangeAlarmAttributes() (CVE-2025-26601) Checksums-Sha1: 1621b97349063781dbcf7eb40434089995bd6411 2724268 xnest-dbgsym_21.1.7-3+deb12u9_ppc64el.deb d8013aeb1aa409567e52554e0c4edcd43fc5385d 3082976 xnest_21.1.7-3+deb12u9_ppc64el.deb f02a53ddb07f4cf6e159b9fa8aa9fe8ad034d7f7 14736 xorg-server_21.1.7-3+deb12u9_ppc64el-buildd.buildinfo 91189aec44a015a49758025940fa0f9cdbd9dc0b 3983648 xserver-xephyr-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 7375cbfd0edad2363b2e970bab329dcf79dbe1ca 3380096 xserver-xephyr_21.1.7-3+deb12u9_ppc64el.deb 0e9a04b40e2b4ed5f773d83f38cceab774e9bf2f 5799100 xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 3006983f1710b9e501dd9273770b63c0fa319427 1042512 xserver-xorg-core-udeb_21.1.7-3+deb12u9_ppc64el.udeb 1e3d1d01ddb30354b311e636d0e2302cd8633933 3825108 xserver-xorg-core_21.1.7-3+deb12u9_ppc64el.deb d86cd6581012193e3189b2e680aad2cecdc561a3 2554512 xserver-xorg-dev_21.1.7-3+deb12u9_ppc64el.deb fbfa40b895ca1c592c39aa3ba0183bbed5cb4f5f 9732 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 6c70bf3a93bfe40b5a59b2e5b20d367df75ce889 2389260 xserver-xorg-legacy_21.1.7-3+deb12u9_ppc64el.deb 10a87306e3bd1da1e23ea04f72e9073378f9998a 3301492 xvfb-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 628e3182a23cef814a0b2c714ab9a5238d02d568 3234692 xvfb_21.1.7-3+deb12u9_ppc64el.deb Checksums-Sha256: ded7683439a843e1933b5b3b5147e7cb6def993b4c70c07605246c9d9979f599 2724268 xnest-dbgsym_21.1.7-3+deb12u9_ppc64el.deb d897a1a547ef21518a1cb1bd60347edc0858aede28bbbe3072b22619f1e49df8 3082976 xnest_21.1.7-3+deb12u9_ppc64el.deb 20f978781cea0c75341ddc1e02caebebb9388e1d85f5927ee4c85495f852d992 14736 xorg-server_21.1.7-3+deb12u9_ppc64el-buildd.buildinfo 37f6a859d52e0ab822888ec277ad5052cd0dc91a4e13f0fa579dc31a9f6b3861 3983648 xserver-xephyr-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 582cecfe364a40468fc87f60f7f9e5bf72e629e6d745d2c046fe98c0defaf916 3380096 xserver-xephyr_21.1.7-3+deb12u9_ppc64el.deb 0b60532d7ce960aa4ba9e747abdf64a7a71238cf45492e82cfce52c338459d37 5799100 xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 99495eea8effc81ca1b0051c06a20575e130055f796ab0389f582b983eb56c06 1042512 xserver-xorg-core-udeb_21.1.7-3+deb12u9_ppc64el.udeb 71cafae6b5c516fe21668a4f1c0e2bc791c79c17b94fc216d1b5a949369da915 3825108 xserver-xorg-core_21.1.7-3+deb12u9_ppc64el.deb 4236dda888609435019e341addd9af75bf9b49b7cb4f2b9e9abb86ff00177aaf 2554512 xserver-xorg-dev_21.1.7-3+deb12u9_ppc64el.deb 415633b1383cadb4ba07e7b5e98e2e9814ae75c5eb8d4c1042dd046773cc8078 9732 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_ppc64el.deb b7be3c5de8680d8f2667d345072e5db22286ccd38ba5dea7c4fe94d91fcbca12 2389260 xserver-xorg-legacy_21.1.7-3+deb12u9_ppc64el.deb ae88f04f34f5471f9b4e0aad158e5b87fcf294adf2a7b049fb3be9dba34e15f9 3301492 xvfb-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 7d7b6427b6fb303522262984d4521fd76f09cb66aa984e5995f145200c17f434 3234692 xvfb_21.1.7-3+deb12u9_ppc64el.deb Files: 1025afe2576180dfb43b594f6b28c08b 2724268 debug optional xnest-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 07989d68bfd4e443a60151c1da81ccf1 3082976 x11 optional xnest_21.1.7-3+deb12u9_ppc64el.deb 46c5dc761c9b22a24953e33a6ddeda41 14736 x11 optional xorg-server_21.1.7-3+deb12u9_ppc64el-buildd.buildinfo fa902b2621d45429175673a73bef7225 3983648 debug optional xserver-xephyr-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 9f3a095cb2e4f691c469baf1b7cec171 3380096 x11 optional xserver-xephyr_21.1.7-3+deb12u9_ppc64el.deb 615c22e2eaa38414776dc3357f719895 5799100 debug optional xserver-xorg-core-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 5392509379698ca75e7570b3ad933a2d 1042512 debian-installer optional xserver-xorg-core-udeb_21.1.7-3+deb12u9_ppc64el.udeb d438dbe64cf366ebeb16b72cf3f1e09c 3825108 x11 optional xserver-xorg-core_21.1.7-3+deb12u9_ppc64el.deb 031ce4621b73da3b6c6d98f894902ac4 2554512 x11 optional xserver-xorg-dev_21.1.7-3+deb12u9_ppc64el.deb 0fc3baa46a2416d23bfefdd400979f77 9732 debug optional xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 87e09dc14d7d727532f284891e66baaf 2389260 x11 optional xserver-xorg-legacy_21.1.7-3+deb12u9_ppc64el.deb 30c5f7a4c014ed088cd0f04606799057 3301492 debug optional xvfb-dbgsym_21.1.7-3+deb12u9_ppc64el.deb 7d2c69c2863e58eaff740755a92e4770 3234692 x11 optional xvfb_21.1.7-3+deb12u9_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvNkWZvjZkiWgJGRETMSrGPLkYxUFAme2LwgACgkQTMSrGPLk YxUhORAAkX38SzcPGoHc/vqtq6WWDZtiaqlJmSx5RJItdg6h2NpKCWPvXyXdBpGh 1H0ciaSQlLUz///G3qyIAKA+7S+Gdmn8UBWdTRYe2E1a5WiND+7RUO4ZWciCi0kC o3QWb/zewgEiNAzr4+yPe/jN49qkZbQKv5Jzx8qieaFyUT9p5YHLqgjuud7DHmXR aOK23l9t7kY17UyilTvomBc0EkPrBF5BprHiIgAcMUfWaVnLEelkIY/jMdf5hJoi bCZ86kdqoq5tkOM5o+ZeuxC4PhGQBX/+eMXVFQSFf5hunxcEBsGiBlq91bgrXhnY Jz3b7Z984b3tu7D42W8IM7We6vEuIMdB9jA5qsrT5mKurRcK1OXEq+gAi0ic7aPt rjHX1Obki+FI6dkkOu3TgrXwPWopsEi6aBRtpPbIaNXay6s5yWYUXBZru7Axe/Sm 146CULNMlA5S6v09horIy0IOShpGp3nxMb74NabBKg+9F0z5ppFbsOE/VYe21pUS 3FlgT4HP003P2+cufBgAx8K47bnzxyBvLUH/Nd/RAeYaT/lb1bau02l67wCuJKup B04JR0TsRYbBtuHe71Srant7VfqqHo/H+1uy3d+ndWtreIyJDTXZRoMW+4xir4J2 pVh7pcpgclJrf1YI4GUa4TjiHGcujuVOW4FusTF8NldUW3PkMQo= =duPR -----END PGP SIGNATURE-----