xorg.xorgserver: 1.20.13 -> 21.1.4#182103
Closed
lheckemann wants to merge 1 commit intoNixOS:masterfrom
Closed
Conversation
This addresses "multiple input validation failures in X server extensions" as reported in https://lists.x.org/archives/xorg/2022-July/061035.html These issues can lead to privilege escalation when the X server is running as root (as it still often does on NixOS), as well as remote code execution via SSH X forwarding. Fixes CVE-2022-2319 Fixes CVE-2022-2320
Member
|
Member
Author
|
gah, how did I miss that... |
Member
|
It wasn't that easy to find on GitHub, but retrospectively I'm surprised that you missed it in the chatroom https://matrix.to/#/#security:nixos.org |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This addresses "multiple input validation failures in X server
extensions" as reported in
https://lists.x.org/archives/xorg/2022-July/061035.html
These issues can lead to privilege escalation when the X server is
running as root (as it still often does on NixOS), as well as remote
code execution via SSH X forwarding.
Fixes CVE-2022-2319
Fixes CVE-2022-2320
I will have a look if we can backport just the security patches, or if we'll need the whole (somewhat unusually numbered) version bump. I suspect that if the patches aren't trivial to backport, the X server is a stable enough piece of software that it should be safe to backport the whole version.
Things done