-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 22 Jan 2024 07:21:42 +0100 Source: xorg-server Architecture: source Version: 2:1.20.11-1+deb11u11 Distribution: bullseye-security Urgency: high Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: xorg-server (2:1.20.11-1+deb11u11) bullseye-security; urgency=high . * Non-maintainer upload by the Security Team. * Xi: require a pointer and keyboard device for XIAttachToMaster * dix: allocate enough space for logical button maps (CVE-2023-6816) * dix: Allocate sufficient xEvents for our DeviceStateNotify (CVE-2024-0229) * dix: fix DeviceStateNotify event calculation (CVE-2024-0229) * Xi: when creating a new ButtonClass, set the number of buttons (CVE-2024-0229) * Xi: flush hierarchy events after adding/removing master devices (CVE-2024-21885) * Xi: do not keep linked list pointer during recursion (CVE-2024-21886) * dix: when disabling a master, float disabled slaved devices too (CVE-2024-21886) * ephyr,xwayland: Use the proper private key for cursor * glx: Call XACE hooks on the GLX buffer * dix: Fix use after free in input device shutdown Checksums-Sha1: e0c52af496da3303f096cf44be49fceab58097d3 4395 xorg-server_1.20.11-1+deb11u11.dsc edc44e7de2ac5ff0d94dd11c7bee6c7266042761 185576 xorg-server_1.20.11-1+deb11u11.diff.gz Checksums-Sha256: 3340b7f80fb04db8ce2570acafc37c00ded8f3cc558d94e07eec04eebd0474ac 4395 xorg-server_1.20.11-1+deb11u11.dsc 78acef7a665647a50b4321921a735930bcb47210649d6e58e2495d2192f60c95 185576 xorg-server_1.20.11-1+deb11u11.diff.gz Files: 2a739ad04c3cfaa47d3201a0f39ba23c 4395 x11 optional xorg-server_1.20.11-1+deb11u11.dsc f3ba7b9da4ba5844b7cba3d049f03075 185576 x11 optional xorg-server_1.20.11-1+deb11u11.diff.gz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmWuDEFfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EyLsP/3fuRYLbhdCFqjeOEaGjeTwve+9PUeRQ Bs01i4KTv3Dm7uZFzsxDX2nW2xvAIWpDp6vGZTXvZH8vZHjImZSdRYCViyKVjywN q1rwH7sEOkY8H6LAgP/YExPi+4AbE7ZB+E/Rq/+5NfW9FjNNndSgMAEnlIDXKPnk W6msxvYGfZF/jVj+dFCSlcTG1bSCEC8LqyDAT/sJQ/5D1puZsYBD9lDm+wM6ldnX B+gquNIUzBLazFRd9xgjirYCCfeGJaKJuDkjf3AClWq23GlE4SCUWCyNgynX8I9l aDXCD6pqgQDB4FXgS1LEhINw/zvVehxy44Gp7saBVEOXYO38kGJ6idJCTKPwaeue lETjUN5yayv37rnO7kNW5ykYRbr0cXA4Wkv+/mvplopWo8VfuYIRXxgIl6+EKAsc DvBaL3qsFLFq9uCRtAi0e3opBmpAcWlSvM+AEIKQDZ4m4UJELwm67sDak9YBXxmP JXX0u8iLb0U0mTuu2LQrZg9A05bb6vnJJSAZrY4lQBNZvAJNLOhYkJ4GrHWHYRVB 5vSW7MGSwl5BmTQ6U1ZUfXXg/2iFVJWByWRAiG9AuXJDUtkmEysqGwTJmpeZT3tk WWhJXfQecd8KcJsvellpeDOHUdCeTqQeGR2iEKRImiK3UcfzhKvKY6jAowqjWTls 33TQxc94HEVV =Fza/ -----END PGP SIGNATURE-----