-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 27 Oct 2025 18:17:17 +0100 Source: xorg-server Architecture: source Version: 2:21.1.7-3+deb12u11 Distribution: bookworm-security Urgency: high Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: xorg-server (2:21.1.7-3+deb12u11) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * present: Fix use-after-free in present_create_notifies() (CVE-2025-62229) * xkb: Make the RT_XKBCLIENT resource private (CVE-2025-62230) * xkb: Free the XKB resource when freeing XkbInterest (CVE-2025-62230) * xkb: Prevent overflow in XkbSetCompatMap() (CVE-2025-62231) Checksums-Sha1: 124ec4393008abb7d1703525c97144e4534086a5 4139 xorg-server_21.1.7-3+deb12u11.dsc 30879e9cfca2ca2a9b1dbcae6793ed036dec06b8 204000 xorg-server_21.1.7-3+deb12u11.diff.gz 8fa6659be4536d4066c89a702b1ddf284d5cfdf8 6908 xorg-server_21.1.7-3+deb12u11_source.buildinfo Checksums-Sha256: 89213c96e7319f2dcd9ca47646554d1bbd36fe5eefcb105e7b0998c8c56e4988 4139 xorg-server_21.1.7-3+deb12u11.dsc 3cbe97440a47fd2f6d866bd65b8b4e599c68c146d7167b3c53aab705cc5d0c44 204000 xorg-server_21.1.7-3+deb12u11.diff.gz f78620189b21a1690c7d3d2e0f2fc28c19c2dabba8c76ee5886bcc91079cff17 6908 xorg-server_21.1.7-3+deb12u11_source.buildinfo Files: c5107a57db9dcf242c4995dc5732cb21 4139 x11 optional xorg-server_21.1.7-3+deb12u11.dsc cfa57d7efde4521907e9a6684f848ae5 204000 x11 optional xorg-server_21.1.7-3+deb12u11.diff.gz da04f04a1eb3fe390a428f242ee55ebb 6908 x11 optional xorg-server_21.1.7-3+deb12u11_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmj/0GtfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EflYQAJUug9nzNEW3kQUwoniqv88TYdpHOqLN oU6sbqRw8WF+3DIKPjc2jZwdMYCsGRfdngIpvswYRKOxOAfLH9g4nJhW6vMN8q8e snzZEx8NU9nZ1SDalZjjsTcOc1P1P/TCRd3Sj+M1jFDoZbwnNMDDNwalH3s5yVc+ dvCbpcDt4Jn8APrCvTYqbZ9ZTbKzAoEBrvlMwPe/rxpkAN2Ymdjvw/elu2YhuhKy tGV0Elzaxfx4VbLK0Si2GtCd30WJjp9xOaRxnTN0lEyVds3CyIGLmRL0Wqs3A2Ml Cnd4qdIVj17n+xP4UKxrhAp75kCVL/tSsyz9Qz7ld5xAr/q6qOOPwq2NNrKn1+Z0 S7qojHVZBXd2TuJD0+mKwYBSh1sVIJh/V0vwTvml7SiKaNjI6+qrhwtj8HeVx+Jz 2PmO0NuYuQloK+eDqh76Mfn7QsLI8a+JnHbdID3IC5n12z8Cw0tj2rXfZ88JL+Fe i6K0M8Vh1s+CyZsS0t8S6RtXYMPca0oeU4+ZjR1H/aZV8XKJG/gbTHgsH5cc01Fj XwPU/iy6jTvYWISM7Z6YA2T6JfIyhS+GfBpx51hUSoRBHB6xX07xCZ7SOUK4zYLB KknHlswcnOYoq/A7Lo31BheltJvVlGtnXppt0rshJD37Wx1TP03xHY2zfnL1vd8M 2zfFQcX+T60r =LCLb -----END PGP SIGNATURE-----