summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorYogita Urade <yogita.urade@windriver.com>2025-11-19 16:34:39 +0530
committerSteve Sakoman <steve@sakoman.com>2025-11-26 07:50:35 -0800
commit33231bec7b6f377d0de94f0aa8d8283c4ca1c62e (patch)
tree91d88c541bfb4c5b299e76a2fe721cd7971ba763
parentdb7f5868228f0be21939c5dfa16ca059a67af9c0 (diff)
downloadpoky-33231bec7b6f377d0de94f0aa8d8283c4ca1c62e.tar.gz
xwayland: fix CVE-2025-62229
A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-62229 Upstream patch: https://gitlab.freedesktop.org/xorg/xserver/-/commit/5a4286b13f631b66c20f5bc8db7b68211dcbd1d0 (From OE-Core rev: 3d606cc94e5ce42b836878578fa271a72bc76015) Signed-off-by: Yogita Urade <yogita.urade@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
-rw-r--r--meta/recipes-graphics/xwayland/xwayland/CVE-2025-62229.patch89
-rw-r--r--meta/recipes-graphics/xwayland/xwayland_23.2.5.bb1
2 files changed, 90 insertions, 0 deletions
diff --git a/meta/recipes-graphics/xwayland/xwayland/CVE-2025-62229.patch b/meta/recipes-graphics/xwayland/xwayland/CVE-2025-62229.patch
new file mode 100644
index 0000000000..f27bd00434
--- /dev/null
+++ b/meta/recipes-graphics/xwayland/xwayland/CVE-2025-62229.patch
@@ -0,0 +1,89 @@
1From 5a4286b13f631b66c20f5bc8db7b68211dcbd1d0 Mon Sep 17 00:00:00 2001
2From: Olivier Fourdan <ofourdan@redhat.com>
3Date: Wed, 2 Jul 2025 09:46:22 +0200
4Subject: [PATCH] present: Fix use-after-free in present_create_notifies()
5
6Using the Present extension, if an error occurs while processing and
7adding the notifications after presenting a pixmap, the function
8present_create_notifies() will clean up and remove the notifications
9it added.
10
11However, there are two different code paths that can lead to an error
12creating the notify, one being before the notify is being added to the
13list, and another one after the notify is added.
14
15When the error occurs before it's been added, it removes the elements up
16to the last added element, instead of the actual number of elements
17which were added.
18
19As a result, in case of error, as with an invalid window for example, it
20leaves a dangling pointer to the last element, leading to a use after
21free case later:
22
23 | Invalid write of size 8
24 | at 0x5361D5: present_clear_window_notifies (present_notify.c:42)
25 | by 0x534A56: present_destroy_window (present_screen.c:107)
26 | by 0x41E441: xwl_destroy_window (xwayland-window.c:1959)
27 | by 0x4F9EC9: compDestroyWindow (compwindow.c:622)
28 | by 0x51EAC4: damageDestroyWindow (damage.c:1592)
29 | by 0x4FDC29: DbeDestroyWindow (dbe.c:1291)
30 | by 0x4EAC55: FreeWindowResources (window.c:1023)
31 | by 0x4EAF59: DeleteWindow (window.c:1091)
32 | by 0x4DE59A: doFreeResource (resource.c:890)
33 | by 0x4DEFB2: FreeClientResources (resource.c:1156)
34 | by 0x4A9AFB: CloseDownClient (dispatch.c:3567)
35 | by 0x5DCC78: ClientReady (connection.c:603)
36 | Address 0x16126200 is 16 bytes inside a block of size 2,048 free'd
37 | at 0x4841E43: free (vg_replace_malloc.c:989)
38 | by 0x5363DD: present_destroy_notifies (present_notify.c:111)
39 | by 0x53638D: present_create_notifies (present_notify.c:100)
40 | by 0x5368E9: proc_present_pixmap_common (present_request.c:164)
41 | by 0x536A7D: proc_present_pixmap (present_request.c:189)
42 | by 0x536FA9: proc_present_dispatch (present_request.c:337)
43 | by 0x4A1E4E: Dispatch (dispatch.c:561)
44 | by 0x4B00F1: dix_main (main.c:284)
45 | by 0x42879D: main (stubmain.c:34)
46 | Block was alloc'd at
47 | at 0x48463F3: calloc (vg_replace_malloc.c:1675)
48 | by 0x5362A1: present_create_notifies (present_notify.c:81)
49 | by 0x5368E9: proc_present_pixmap_common (present_request.c:164)
50 | by 0x536A7D: proc_present_pixmap (present_request.c:189)
51 | by 0x536FA9: proc_present_dispatch (present_request.c:337)
52 | by 0x4A1E4E: Dispatch (dispatch.c:561)
53 | by 0x4B00F1: dix_main (main.c:284)
54 | by 0x42879D: main (stubmain.c:34)
55
56To fix the issue, count and remove the actual number of notify elements
57added in case of error.
58
59CVE-2025-62229, ZDI-CAN-27238
60
61This vulnerability was discovered by:
62Jan-Niklas Sohn working with Trend Micro Zero Day Initiative
63
64Signed-off-by: Olivier Fourdan <ofourdan@redhat.com>
65Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2086>
66
67CVE: CVE-2025-62229
68Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/xserver/-/commit/5a4286b13f631b66c20f5bc8db7b68211dcbd1d0]
69
70Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
71---
72 present/present_notify.c | 2 +-
73 1 file changed, 1 insertion(+), 1 deletion(-)
74
75diff --git a/present/present_notify.c b/present/present_notify.c
76index 4459549..00b3b68 100644
77--- a/present/present_notify.c
78+++ b/present/present_notify.c
79@@ -90,7 +90,7 @@ present_create_notifies(ClientPtr client, int num_notifies, xPresentNotify *x_no
80 if (status != Success)
81 goto bail;
82
83- added = i;
84+ added++;
85 }
86 return Success;
87
88--
892.40.0
diff --git a/meta/recipes-graphics/xwayland/xwayland_23.2.5.bb b/meta/recipes-graphics/xwayland/xwayland_23.2.5.bb
index 49e35ca442..1ed5df8a2e 100644
--- a/meta/recipes-graphics/xwayland/xwayland_23.2.5.bb
+++ b/meta/recipes-graphics/xwayland/xwayland_23.2.5.bb
@@ -31,6 +31,7 @@ SRC_URI = "https://www.x.org/archive/individual/xserver/xwayland-${PV}.tar.xz \
31 file://CVE-2025-49178.patch \ 31 file://CVE-2025-49178.patch \
32 file://CVE-2025-49179.patch \ 32 file://CVE-2025-49179.patch \
33 file://CVE-2025-49180.patch \ 33 file://CVE-2025-49180.patch \
34 file://CVE-2025-62229.patch \
34" 35"
35SRC_URI[sha256sum] = "33ec7ff2687a59faaa52b9b09aa8caf118e7ecb6aed8953f526a625ff9f4bd90" 36SRC_URI[sha256sum] = "33ec7ff2687a59faaa52b9b09aa8caf118e7ecb6aed8953f526a625ff9f4bd90"
36 37