<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-graphics/xorg-xserver, branch hardknott</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=hardknott</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=hardknott'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2022-01-25T12:07:01+00:00</updated>
<entry>
<title>xserver-xorg: whitelist two CVEs</title>
<updated>2022-01-25T12:07:01+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross@burtonini.com</email>
</author>
<published>2022-01-10T12:19:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=3314a8f59ec5ae4d4637eefc96bedc7b57a55eb7'/>
<id>urn:sha1:3314a8f59ec5ae4d4637eefc96bedc7b57a55eb7</id>
<content type='text'>
CVE-2011-4613 is specific to Debian/Ubuntu.

CVE-2020-25697 is a non-trivial attack that may not actually be feasible
considering the default behaviour for clients is to exit if the
connection is lost.

(From OE-Core rev: f82c65b3c69738401ecdac354ed65308929cc20f)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit afa2e6c31a79f75ff4113d53f618bbb349cd6c17)
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>xserver-xorg: update CVE_PRODUCT</title>
<updated>2022-01-07T23:21:34+00:00</updated>
<author>
<name>Anuj Mittal</name>
<email>anuj.mittal@intel.com</email>
</author>
<published>2021-12-29T01:34:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=1c6ee8a737cf4f8679c6081858635809ae8bef88'/>
<id>urn:sha1:1c6ee8a737cf4f8679c6081858635809ae8bef88</id>
<content type='text'>
Some of the CVEs have x_server as the product name.

(From OE-Core rev: 1f86315f5993ddaafddb99da536bb1a51786fe59)

Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 4d5d63cf8605515bb659b6b732683d7fe6540728)
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>xserver-xorg: fix CVE-2021-4011</title>
<updated>2022-01-07T23:21:34+00:00</updated>
<author>
<name>Kai Kang</name>
<email>kai.kang@windriver.com</email>
</author>
<published>2021-12-28T09:29:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=c7cd0868ce7e19e318c4aa061e318dbeeae1e2d9'/>
<id>urn:sha1:c7cd0868ce7e19e318c4aa061e318dbeeae1e2d9</id>
<content type='text'>
Backport patch to fix CVE-2021-4011 for xserver-xorg.

CVE: CVE-2021-4011

(From OE-Core rev: 5f300f2be6453947a37231ced56ca577c91d93b4)

Signed-off-by: Kai Kang &lt;kai.kang@windriver.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>xserver-xorg: fix CVE-2021-4010</title>
<updated>2022-01-07T23:21:34+00:00</updated>
<author>
<name>Kai Kang</name>
<email>kai.kang@windriver.com</email>
</author>
<published>2021-12-28T09:29:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=b6e3bbc1deaaa75ee26a8ef0f23eb0b3203c56e0'/>
<id>urn:sha1:b6e3bbc1deaaa75ee26a8ef0f23eb0b3203c56e0</id>
<content type='text'>
Backport patch to fix CVE-2021-4010 for xserver-xorg.

CVE: CVE-2021-4010

(From OE-Core rev: 487971876baa9913541a187d98deddc00e60d3f8)

Signed-off-by: Kai Kang &lt;kai.kang@windriver.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>xserver-xorg: fix CVE-2021-4009</title>
<updated>2022-01-07T23:21:34+00:00</updated>
<author>
<name>Kai Kang</name>
<email>kai.kang@windriver.com</email>
</author>
<published>2021-12-28T09:29:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=cf5da90349232565c9507fcf0cf333c2b7fa425b'/>
<id>urn:sha1:cf5da90349232565c9507fcf0cf333c2b7fa425b</id>
<content type='text'>
Backport patch to fix CVE-2021-4009 for xserver-xorg.

CVE: CVE-2021-4009

(From OE-Core rev: 33581b19a2eb00b5905325e966edd7f7519a2924)

Signed-off-by: Kai Kang &lt;kai.kang@windriver.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>xserver-xorg: fix CVE-2021-4008</title>
<updated>2022-01-07T23:21:34+00:00</updated>
<author>
<name>Kai Kang</name>
<email>kai.kang@windriver.com</email>
</author>
<published>2021-12-28T09:29:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=c6f04bb30342174663901eac5891bc7de0cc7b47'/>
<id>urn:sha1:c6f04bb30342174663901eac5891bc7de0cc7b47</id>
<content type='text'>
Backport patch to fix CVE-2021-4008 for xserver-xorg.

CVE: CVE-2021-4008

(From OE-Core rev: e975b1741209e298c3b6a5b101c93e1c17dbced6)

Signed-off-by: Kai Kang &lt;kai.kang@windriver.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>xserver-xorg: Fix builds without glx</title>
<updated>2021-07-20T18:05:45+00:00</updated>
<author>
<name>Wadim Egorov</name>
<email>w.egorov@phytec.de</email>
</author>
<published>2021-07-13T12:29:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=bbaf7ae626028c42fe1939a79c2b17fbc8d3263c'/>
<id>urn:sha1:bbaf7ae626028c42fe1939a79c2b17fbc8d3263c</id>
<content type='text'>
(From OE-Core rev: e458c15627e7b27392d158cbb9417f66424aa7d5)

Signed-off-by: Wadim Egorov &lt;w.egorov@phytec.de&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>xserver-xorg: fix CVE-2021-3472</title>
<updated>2021-05-11T11:02:29+00:00</updated>
<author>
<name>Stefan Ghinea</name>
<email>stefan.ghinea@windriver.com</email>
</author>
<published>2021-04-29T17:15:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=b35658c7fc1258680069fbff3c6b88d0deb5f489'/>
<id>urn:sha1:b35658c7fc1258680069fbff3c6b88d0deb5f489</id>
<content type='text'>
Insufficient checks on the lengths of the XInput extension
ChangeFeedbackControl request can lead to out of bounds memory accesses
in the X server.

References:
https://nvd.nist.gov/vuln/detail/CVE-2021-3472

Upstream patches:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/7aaf54a1884f71dc363f0b884e57bcb67407a6cd

(From OE-Core rev: 8fbf485f24711ab29972841ba52dcb9dcdabaffb)

Signed-off-by: Stefan Ghinea &lt;stefan.ghinea@windriver.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 6fec5fea942ce88e33e5cf4c2102d69ce25e7180)
Signed-off-by: Anuj Mittal &lt;anuj.mittal@intel.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>xserver-xorg: upgrade 1.20.9 -&gt; 1.20.10</title>
<updated>2020-12-30T14:01:06+00:00</updated>
<author>
<name>Alexander Kanavin</name>
<email>alex.kanavin@gmail.com</email>
</author>
<published>2020-12-26T09:27:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=e43a1b06bde93244453075c79e28b02ab90d5e63'/>
<id>urn:sha1:e43a1b06bde93244453075c79e28b02ab90d5e63</id>
<content type='text'>
(From OE-Core rev: 3b03545ea141a9b6c38742aea6e8464e1a1b2a26)

Signed-off-by: Alexander Kanavin &lt;alex.kanavin@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>meta: add/fix invalid Upstream-Status tags</title>
<updated>2020-09-23T19:54:03+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross@burtonini.com</email>
</author>
<published>2020-09-22T14:42:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=bb759f56f6f4f63750bdeb2ddf75b9a080764221'/>
<id>urn:sha1:bb759f56f6f4f63750bdeb2ddf75b9a080764221</id>
<content type='text'>
(From OE-Core rev: 630ce8130598e2bca7231ac28a7cc18b5b942544)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
</feed>
