diff options
| author | Yogita Urade <yogita.urade@windriver.com> | 2025-11-19 16:34:39 +0530 |
|---|---|---|
| committer | Steve Sakoman <steve@sakoman.com> | 2025-11-26 07:50:35 -0800 |
| commit | 33231bec7b6f377d0de94f0aa8d8283c4ca1c62e (patch) | |
| tree | 91d88c541bfb4c5b299e76a2fe721cd7971ba763 | |
| parent | db7f5868228f0be21939c5dfa16ca059a67af9c0 (diff) | |
| download | poky-33231bec7b6f377d0de94f0aa8d8283c4ca1c62e.tar.gz | |
xwayland: fix CVE-2025-62229
A flaw was found in the X.Org X server and Xwayland when processing
X11 Present extension notifications. Improper error handling during
notification creation can leave dangling pointers that lead to a
use-after-free condition. This can cause memory corruption or a crash,
potentially allowing an attacker to execute arbitrary code or cause a
denial of service.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-62229
Upstream patch:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/5a4286b13f631b66c20f5bc8db7b68211dcbd1d0
(From OE-Core rev: 3d606cc94e5ce42b836878578fa271a72bc76015)
Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
| -rw-r--r-- | meta/recipes-graphics/xwayland/xwayland/CVE-2025-62229.patch | 89 | ||||
| -rw-r--r-- | meta/recipes-graphics/xwayland/xwayland_23.2.5.bb | 1 |
2 files changed, 90 insertions, 0 deletions
diff --git a/meta/recipes-graphics/xwayland/xwayland/CVE-2025-62229.patch b/meta/recipes-graphics/xwayland/xwayland/CVE-2025-62229.patch new file mode 100644 index 0000000000..f27bd00434 --- /dev/null +++ b/meta/recipes-graphics/xwayland/xwayland/CVE-2025-62229.patch | |||
| @@ -0,0 +1,89 @@ | |||
| 1 | From 5a4286b13f631b66c20f5bc8db7b68211dcbd1d0 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Olivier Fourdan <ofourdan@redhat.com> | ||
| 3 | Date: Wed, 2 Jul 2025 09:46:22 +0200 | ||
| 4 | Subject: [PATCH] present: Fix use-after-free in present_create_notifies() | ||
| 5 | |||
| 6 | Using the Present extension, if an error occurs while processing and | ||
| 7 | adding the notifications after presenting a pixmap, the function | ||
| 8 | present_create_notifies() will clean up and remove the notifications | ||
| 9 | it added. | ||
| 10 | |||
| 11 | However, there are two different code paths that can lead to an error | ||
| 12 | creating the notify, one being before the notify is being added to the | ||
| 13 | list, and another one after the notify is added. | ||
| 14 | |||
| 15 | When the error occurs before it's been added, it removes the elements up | ||
| 16 | to the last added element, instead of the actual number of elements | ||
| 17 | which were added. | ||
| 18 | |||
| 19 | As a result, in case of error, as with an invalid window for example, it | ||
| 20 | leaves a dangling pointer to the last element, leading to a use after | ||
| 21 | free case later: | ||
| 22 | |||
| 23 | | Invalid write of size 8 | ||
| 24 | | at 0x5361D5: present_clear_window_notifies (present_notify.c:42) | ||
| 25 | | by 0x534A56: present_destroy_window (present_screen.c:107) | ||
| 26 | | by 0x41E441: xwl_destroy_window (xwayland-window.c:1959) | ||
| 27 | | by 0x4F9EC9: compDestroyWindow (compwindow.c:622) | ||
| 28 | | by 0x51EAC4: damageDestroyWindow (damage.c:1592) | ||
| 29 | | by 0x4FDC29: DbeDestroyWindow (dbe.c:1291) | ||
| 30 | | by 0x4EAC55: FreeWindowResources (window.c:1023) | ||
| 31 | | by 0x4EAF59: DeleteWindow (window.c:1091) | ||
| 32 | | by 0x4DE59A: doFreeResource (resource.c:890) | ||
| 33 | | by 0x4DEFB2: FreeClientResources (resource.c:1156) | ||
| 34 | | by 0x4A9AFB: CloseDownClient (dispatch.c:3567) | ||
| 35 | | by 0x5DCC78: ClientReady (connection.c:603) | ||
| 36 | | Address 0x16126200 is 16 bytes inside a block of size 2,048 free'd | ||
| 37 | | at 0x4841E43: free (vg_replace_malloc.c:989) | ||
| 38 | | by 0x5363DD: present_destroy_notifies (present_notify.c:111) | ||
| 39 | | by 0x53638D: present_create_notifies (present_notify.c:100) | ||
| 40 | | by 0x5368E9: proc_present_pixmap_common (present_request.c:164) | ||
| 41 | | by 0x536A7D: proc_present_pixmap (present_request.c:189) | ||
| 42 | | by 0x536FA9: proc_present_dispatch (present_request.c:337) | ||
| 43 | | by 0x4A1E4E: Dispatch (dispatch.c:561) | ||
| 44 | | by 0x4B00F1: dix_main (main.c:284) | ||
| 45 | | by 0x42879D: main (stubmain.c:34) | ||
| 46 | | Block was alloc'd at | ||
| 47 | | at 0x48463F3: calloc (vg_replace_malloc.c:1675) | ||
| 48 | | by 0x5362A1: present_create_notifies (present_notify.c:81) | ||
| 49 | | by 0x5368E9: proc_present_pixmap_common (present_request.c:164) | ||
| 50 | | by 0x536A7D: proc_present_pixmap (present_request.c:189) | ||
| 51 | | by 0x536FA9: proc_present_dispatch (present_request.c:337) | ||
| 52 | | by 0x4A1E4E: Dispatch (dispatch.c:561) | ||
| 53 | | by 0x4B00F1: dix_main (main.c:284) | ||
| 54 | | by 0x42879D: main (stubmain.c:34) | ||
| 55 | |||
| 56 | To fix the issue, count and remove the actual number of notify elements | ||
| 57 | added in case of error. | ||
| 58 | |||
| 59 | CVE-2025-62229, ZDI-CAN-27238 | ||
| 60 | |||
| 61 | This vulnerability was discovered by: | ||
| 62 | Jan-Niklas Sohn working with Trend Micro Zero Day Initiative | ||
| 63 | |||
| 64 | Signed-off-by: Olivier Fourdan <ofourdan@redhat.com> | ||
| 65 | Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2086> | ||
| 66 | |||
| 67 | CVE: CVE-2025-62229 | ||
| 68 | Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/xserver/-/commit/5a4286b13f631b66c20f5bc8db7b68211dcbd1d0] | ||
| 69 | |||
| 70 | Signed-off-by: Yogita Urade <yogita.urade@windriver.com> | ||
| 71 | --- | ||
| 72 | present/present_notify.c | 2 +- | ||
| 73 | 1 file changed, 1 insertion(+), 1 deletion(-) | ||
| 74 | |||
| 75 | diff --git a/present/present_notify.c b/present/present_notify.c | ||
| 76 | index 4459549..00b3b68 100644 | ||
| 77 | --- a/present/present_notify.c | ||
| 78 | +++ b/present/present_notify.c | ||
| 79 | @@ -90,7 +90,7 @@ present_create_notifies(ClientPtr client, int num_notifies, xPresentNotify *x_no | ||
| 80 | if (status != Success) | ||
| 81 | goto bail; | ||
| 82 | |||
| 83 | - added = i; | ||
| 84 | + added++; | ||
| 85 | } | ||
| 86 | return Success; | ||
| 87 | |||
| 88 | -- | ||
| 89 | 2.40.0 | ||
diff --git a/meta/recipes-graphics/xwayland/xwayland_23.2.5.bb b/meta/recipes-graphics/xwayland/xwayland_23.2.5.bb index 49e35ca442..1ed5df8a2e 100644 --- a/meta/recipes-graphics/xwayland/xwayland_23.2.5.bb +++ b/meta/recipes-graphics/xwayland/xwayland_23.2.5.bb | |||
| @@ -31,6 +31,7 @@ SRC_URI = "https://www.x.org/archive/individual/xserver/xwayland-${PV}.tar.xz \ | |||
| 31 | file://CVE-2025-49178.patch \ | 31 | file://CVE-2025-49178.patch \ |
| 32 | file://CVE-2025-49179.patch \ | 32 | file://CVE-2025-49179.patch \ |
| 33 | file://CVE-2025-49180.patch \ | 33 | file://CVE-2025-49180.patch \ |
| 34 | file://CVE-2025-62229.patch \ | ||
| 34 | " | 35 | " |
| 35 | SRC_URI[sha256sum] = "33ec7ff2687a59faaa52b9b09aa8caf118e7ecb6aed8953f526a625ff9f4bd90" | 36 | SRC_URI[sha256sum] = "33ec7ff2687a59faaa52b9b09aa8caf118e7ecb6aed8953f526a625ff9f4bd90" |
| 36 | 37 | ||
