[ANNOUNCE] xorg-server 21.1.7

Peter Hutterer peter.hutterer at who-t.net
Tue Feb 7 01:26:40 UTC 2023


xserver 21.1.7 is now available.

This release contains the fix for CVE-2023-0494 in today's security
advisory: https://lists.x.org/archives/xorg-announce/2023-February/003320.html
It also fixes a second possible OOB access during EnqueueEvent and a
crasher caused by ResourceClientBits not correctly honouring the
MaxClients value in the configuration file.

Finally, a bunch of Xquartz updates including the ability to correctly detect
ssh-tunneled clients as remote.

Jeremy Huddleston Sequoia (11):
      xquartz: Ignore SIGPIPE at process launch
      xquartz: Use xorg_backtrace() instead of rolling our own for debugging
      rootless: Add additional debug logging to help triage XQuartz fb/rootless/damage crashes
      xquartz: Fix building with autoconf
      xquartz: Update the about box copyright to 2023
      xquartz: Disable COMPOSITE at runtime
      Revert "meson: Don't build COMPOSITE for XQuartz"
      os: Update AllocNewConnection() debug logging to include whether or not the client is local
      os: Update GetLocalClientCreds to prefer getpeerucred() or SO_PEERCRED over getpeereid()
      os: Use LOCAL_PEERPID from sys/un.h if it is available to detemine the pid when falling back on getpeereids()
      darwin: Implement DetermineClientCmd for macOS

Mike Gorse (1):
      dix: Use CopyPartialInternalEvent in EnqueueEvent

Olivier Fourdan (1):
      dix: Fix overzealous caching of ResourceClientBits()

Peter Hutterer (2):
      Xi: fix potential use-after-free in DeepCopyPointerClasses
      xserver 21.1.7

git tag: xorg-server-21.1.7

https://xorg.freedesktop.org/archive/individual/xserver/xorg-server-21.1.7.tar.gz
SHA256: 1a9005f47c7ea83645a977581324439628a32c4426303e5a4b9c2d6615becfbf  xorg-server-21.1.7.tar.gz
SHA512: ac9dd13abfd4ce95febd189c7801992cdbf3eafd66f8a2c94c1b4929399a49cb2ae9345fb383fa0606567f29e6dbd530c2cb31aac9a3d816da1ee5a96ad3e1df  xorg-server-21.1.7.tar.gz
PGP:  https://xorg.freedesktop.org/archive/individual/xserver/xorg-server-21.1.7.tar.gz.sig

https://xorg.freedesktop.org/archive/individual/xserver/xorg-server-21.1.7.tar.xz
SHA256: d9c60b2dd0ec52326ca6ab20db0e490b1ff4f566f59ca742d6532e92795877bb  xorg-server-21.1.7.tar.xz
SHA512: e2a093381e28da9b2aa700c6609349fa851f4ca8df23c776f30e4e2733e7a6c1b257576b93f4c4e87fb09df901385bf52528982f6e7a6ad469597aeae8640bb5  xorg-server-21.1.7.tar.xz
PGP:  https://xorg.freedesktop.org/archive/individual/xserver/xorg-server-21.1.7.tar.xz.sig

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
URL: <https://lists.x.org/archives/xorg-announce/attachments/20230207/cb80fc82/attachment.sig>


More information about the xorg-announce mailing list