<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-graphics/xorg-lib, branch mickledore</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=mickledore</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=mickledore'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2023-11-11T18:23:01+00:00</updated>
<entry>
<title>pixman: ignore CVE-2023-37769</title>
<updated>2023-11-11T18:23:01+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-11-03T13:28:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=c97d2f0f0961a7d524beb7716d24aa249980e604'/>
<id>urn:sha1:c97d2f0f0961a7d524beb7716d24aa249980e604</id>
<content type='text'>
This issue relates to a floating point exception in stress-test, which
is an unlikely security exploit at the best of times, but the test is
not installed so isn't relevant.

(From OE-Core rev: 3625bed6d7432091bfb144314b8ef979b5246e4c)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit a36d62a06be6cce1a438f8f2178eb60aad6b7267)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libxpm: upgrade to 3.5.17</title>
<updated>2023-10-25T14:51:01+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-10-04T21:43:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=57fb41f5c6ef03a6df4a4a3f848b6ed66eebdc2b'/>
<id>urn:sha1:57fb41f5c6ef03a6df4a4a3f848b6ed66eebdc2b</id>
<content type='text'>
This release fixes the following CVEs:

- CVE-2023-43788
- CVE-2023-43789

(From OE-Core rev: b4596281de1f96fdf6533ab4caa957f1eaeff756)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 46dd8ce41756dbc2aa0f9001416f208cced1c8d5)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libx11: upgrade to 1.8.7</title>
<updated>2023-10-25T14:51:01+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-10-04T21:43:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=d441582b0673f69f2cf56081e6b5d7992a78fe4c'/>
<id>urn:sha1:d441582b0673f69f2cf56081e6b5d7992a78fe4c</id>
<content type='text'>
This incorporates fixes for the following CVEs:

- CVE-2023-43785
- CVE-2023-43786
- CVE-2023-43787

(From OE-Core rev: 79f9c062df37ca15649d41bb6501e6fab2d73114)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit a1534bb34b680bfc5cb2f35b5fd5a0c2afed6368)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libxkbcommon: add CVE_PRODUCT</title>
<updated>2023-10-13T14:31:05+00:00</updated>
<author>
<name>Emil Kronborg Andersen</name>
<email>emkan@prevas.dk</email>
</author>
<published>2023-08-24T13:41:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=d61e137c1a7ff48c57cd4506411bdce940309abb'/>
<id>urn:sha1:d61e137c1a7ff48c57cd4506411bdce940309abb</id>
<content type='text'>
(From OE-Core rev: 7d395b97e864bb081866eb029168aee7335ed98e)

Signed-off-by: Emil Kronborg Andersen &lt;emkan@prevas.dk&gt;
(cherry picked from commit a23a4a3f156f5758dc4d9dcf1ab27c74302eb2a8)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>pixman: avoid neon on unsupported machines</title>
<updated>2023-10-11T13:54:46+00:00</updated>
<author>
<name>Benjamin Bara</name>
<email>benjamin.bara@skidata.com</email>
</author>
<published>2023-09-04T08:04:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=974832c9cb90e2ae547d4127a607f422963c077c'/>
<id>urn:sha1:974832c9cb90e2ae547d4127a607f422963c077c</id>
<content type='text'>
Disable neon if the machine does not support it.

(From OE-Core rev: dfc65be35a38bc84134aa7d9e3483b1e00b95729)

Signed-off-by: Benjamin Bara &lt;benjamin.bara@skidata.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 9ea1a98bcfe30a46898765e41e0fc9ebb0086738)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>pixman: Remove duplication of license MIT</title>
<updated>2023-09-04T14:13:25+00:00</updated>
<author>
<name>Poonam Jadhav</name>
<email>ppjadhav456@gmail.com</email>
</author>
<published>2023-08-17T07:55:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=b872e1c4adbe93f4909c1bc9e554d854561cb28d'/>
<id>urn:sha1:b872e1c4adbe93f4909c1bc9e554d854561cb28d</id>
<content type='text'>
Remove duplication of license MIT from pixman bbfile.

(From OE-Core rev: 0a14def83fe2bb4f4cc7cf988c7d31d3108e0ed0)

Signed-off-by: Poonam Jadhav &lt;poonam.jadhav@kpit.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit e6c87b267252376ca85b534e3c9ee9b77ff665ca)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libx11: upgrade 1.8.5 -&gt; 1.8.6</title>
<updated>2023-07-20T22:10:40+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2023-06-27T07:17:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=b6168e0810aca56c7efccfa069f9ea1b7fe28025'/>
<id>urn:sha1:b6168e0810aca56c7efccfa069f9ea1b7fe28025</id>
<content type='text'>
Changelog:
==========
InitExt.c: Add bounds checks for extension request, event, &amp; error codes
Fixes CVE-2023-3138

(From OE-Core rev: 5d6169ec81cc260fccb3b65082100e0ef6102046)

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 49b74259b196454d22fcca8b8ecc1c0d41487285)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libx11: upgrade 1.8.4 -&gt; 1.8.5</title>
<updated>2023-07-07T14:30:25+00:00</updated>
<author>
<name>Alexander Kanavin</name>
<email>alex.kanavin@gmail.com</email>
</author>
<published>2023-06-14T09:28:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=325ebef42f1a43a394edf2e621806ab68a3c48f7'/>
<id>urn:sha1:325ebef42f1a43a394edf2e621806ab68a3c48f7</id>
<content type='text'>
Bug fix release

 * autoconf &amp; libtool updates (!187, !188)
 * Restore missing text in XSetScreenSaver man page (#187, !203)
 * Update am_ET.UTF-8 compose keys to use dead-vowel symbols,
   in coordination with xkeyboard-config 2.39 (!205)
 * Assorted updates to en_US.UTF-8 compose keys (!189, !195, !196, !198,
   !199, !200, !201, !207, !208, !209)

(From OE-Core rev: fe81e39b0bac276bda508e4b2667c81c052392e2)

Signed-off-by: Alexander Kanavin &lt;alex@linutronix.de&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 4e931f490854100c2504ce771d5c920e3a62efdd)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libxpm: upgrade 3.5.15 -&gt; 3.5.16</title>
<updated>2023-06-24T19:13:07+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2023-06-01T09:03:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=cb605dd2b070156f48fbfb6e885285bb8718e826'/>
<id>urn:sha1:cb605dd2b070156f48fbfb6e885285bb8718e826</id>
<content type='text'>
Changelog:
===========
test: skip compressed file tests when --disable-open-zfile is used
itlab CI: build with each of --enable-open-zfile &amp; --disable-open-zfile
configure: correct error message to suggest --disable-open-zfile
Fix a memleak in ParsePixels error code path
Fix CVE-2022-44617: Runaway loop with width of 0 and enormous height
open-zfile: Make compress &amp; uncompress commands optional
Require LT_INIT from libtool 2 instead of deprecated AC_PROG_LIBTOOL
test: Use PACKAGE_BUGREPORT instead of hard-coded URL's
test: Add simple test cases for functions in src/rgb.c
xpmReadRgbNames: constify filename argument
XpmCreateDataFromXpmImage: Fix misleading indentation
parse.c: Wrap FREE_CIDX definition in do { ... } while(0)
parse.c: remove unused function xstrlcpy()

(From OE-Core rev: 145d19c86d61761d7446f6776c4cbc8274c06861)

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
(cherry picked from commit 4d9f0958eecdf683434d77a4f65611803cffd247)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libxft: upgrade 2.3.7 -&gt; 2.3.8</title>
<updated>2023-06-24T19:13:07+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2023-06-01T09:03:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=ad1d287d27ab5eeffd5ae23aca5b53491999520b'/>
<id>urn:sha1:ad1d287d27ab5eeffd5ae23aca5b53491999520b</id>
<content type='text'>
Changelog:
=========
add check for missing glyph in XftFontCheckGlyph()
issue 17: libxft-2.3.7: Bold fonts in urxvt missing leftmost pixels
issue 18: Problems with rotated text (monospace font only)
configure: Use LT_INIT from libtool 2 instead of deprecated AC_PROG_LIBTOOL
Clears autoconf warnings

(From OE-Core rev: eb918993806029bde27ea8d799c37b6d007fdb40)

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
(cherry picked from commit 5f6eae1dfb910347ab47ca868e6978768fb14f46)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
</feed>
