Skip to content
GitLab
Explore
Sign in
Register
Primary navigation
Search or go to…
Project
X
xorg-server
Manage
Activity
Members
Labels
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Model registry
Operate
Environments
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Terms and privacy
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
pkg
xorg-server
Merge requests
!72
Update from debian/bullseye-security for apertis/v2023-security
Code
Review changes
Check out branch
Download
Patches
Plain diff
Merged
Update from debian/bullseye-security for apertis/v2023-security
proposed-updates/debian/bullseye-security/191a8a6e
into
apertis/v2023-security
Overview
0
Commits
3
Pipelines
5
Changes
15
Merged
Apertis CI robot
requested to merge
proposed-updates/debian/bullseye-security/191a8a6e
into
apertis/v2023-security
11 months ago
Overview
0
Commits
3
Pipelines
5
Changes
15
Expand
0
0
Merge request reports
Compare
apertis/v2023-security
version 3
d2516b02
11 months ago
version 2
88909f68
11 months ago
version 1
bd33c3ca
11 months ago
apertis/v2023-security (base)
and
latest version
latest version
09c05a09
3 commits,
11 months ago
version 3
d2516b02
5 commits,
11 months ago
version 2
88909f68
4 commits,
11 months ago
version 1
bd33c3ca
3 commits,
11 months ago
15 files
+
500
−
74
Inline
Compare changes
Side-by-side
Inline
Show whitespace changes
Show one file at a time
Files
15
Search (e.g. *.vue) (Ctrl+P)
debian/patches/20240403/0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch
0 → 100644
+
61
−
0
Options
From 8a7cd0e3ef194610300c1a38fb5a5423b23dd6a5 Mon Sep 17 00:00:00 2001
From: Alan Coopersmith <alan.coopersmith@oracle.com>
Date: Fri, 22 Mar 2024 18:51:45 -0700
Subject: [PATCH 1/4] Xi: ProcXIGetSelectedEvents needs to use unswapped length
to send reply
CVE-2024-31080
Reported-by: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=69762
Fixes: 53e821ab4 ("Xi: add request processing for XIGetSelectedEvents.")
Signed-off-by: Alan Coopersmith <alan.coopersmith@oracle.com>
Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1463>
(cherry picked from commit 96798fc1967491c80a4d0c8d9e0a80586cb2152b)
---
Xi/xiselectev.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/Xi/xiselectev.c
+++ b/Xi/xiselectev.c
@@ -292,16 +292,17 @@
ProcXIGetSelectedEvents(ClientPtr client
int rc, i;
WindowPtr win;
char *buffer = NULL;
xXIGetSelectedEventsReply reply;
OtherInputMasks *masks;
InputClientsPtr others = NULL;
xXIEventMask *evmask = NULL;
DeviceIntPtr dev;
+ uint32_t length;
REQUEST(xXIGetSelectedEventsReq);
REQUEST_SIZE_MATCH(xXIGetSelectedEventsReq);
rc = dixLookupWindow(&win, stuff->win, client, DixGetAttrAccess);
if (rc != Success)
return rc;
@@ -361,20 +362,22 @@
ProcXIGetSelectedEvents(ClientPtr client
memcpy(&evmask[1], devmask, j + 1);
evmask = (xXIEventMask *) ((char *) evmask +
sizeof(xXIEventMask) + mask_len * 4);
break;
}
}
}
+ /* save the value before SRepXIGetSelectedEvents swaps it */
+ length = reply.length;
WriteReplyToClient(client, sizeof(xXIGetSelectedEventsReply), &reply);
if (reply.num_masks)
- WriteToClient(client, reply.length * 4, buffer);
+ WriteToClient(client, length * 4, buffer);
free(buffer);
return Success;
}
void
SRepXIGetSelectedEvents(ClientPtr client,
int len, xXIGetSelectedEventsReply * rep)
Loading