[ALSA-2023:2249] Moderate: xorg-x11-server-Xwayland security update
Release date:
Xwayland is an X server for running X clients under Wayland. Security Fix(es): * xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: XkbGetKbdByName use-after-free (CVE-2022-4283) * xorg-x11-server: XTestSwapFakeInput stack overflow (CVE-2022-46340) * xorg-x11-server: XIPassiveUngrab out-of-bounds access (CVE-2022-46341) * xorg-x11-server: XvdiSelectVideoNotify use-after-free (CVE-2022-46342) * xorg-x11-server: ScreenSaverSetAttributes use-after-free (CVE-2022-46343) * xorg-x11-server: XIChangeProperty out-of-bounds access (CVE-2022-46344) * xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 xorg-x11-server-Xwayland-21.1.3-7.el9.aarch64.rpm ba61e1963df36dcb958f61962ef134f7d9ef2aca3a46957a1a44bff041234cc5
ppc64le xorg-x11-server-Xwayland-21.1.3-7.el9.ppc64le.rpm 5e5c6d79c383733873dd6132fe349801794ef5547989254398b9143d1ac22865
s390x xorg-x11-server-Xwayland-21.1.3-7.el9.s390x.rpm 0de9fadda6bc1d4c64e49f3d9b8b6cc813867779cc4d69f1034a2bb191a7f334
x86_64 xorg-x11-server-Xwayland-21.1.3-7.el9.x86_64.rpm f69f0e919bb845f7c7250c4d4657db1c83f612b180f355f1e6e1d93c72caa266
