-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 20 Jun 2025 14:46:37 +0200 Source: xorg-server Binary: xnest xnest-dbgsym xserver-xephyr xserver-xephyr-dbgsym xserver-xorg-core xserver-xorg-core-dbgsym xserver-xorg-core-udeb xserver-xorg-dev xserver-xorg-legacy xserver-xorg-legacy-dbgsym xvfb xvfb-dbgsym Architecture: mips64el Version: 2:21.1.7-3+deb12u10 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Salvatore Bonaccorso Description: xnest - Nested X server xserver-xephyr - nested X server xserver-xorg-core - Xorg X server - core server xserver-xorg-core-udeb - Xorg X server - core server (udeb) xserver-xorg-dev - Xorg X server - development files xserver-xorg-legacy - setuid root Xorg server wrapper xvfb - Virtual Framebuffer 'fake' X server Changes: xorg-server (2:21.1.7-3+deb12u10) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * render: Avoid 0 or less animated cursors (CVE-2025-49175) * os: Do not overflow the integer size with BigRequest (CVE-2025-49176) * xfixes: Check request length for SetClientDisconnectMode (CVE-2025-49177) * os: Account for bytes to ignore when sharing input buffer (CVE-2025-49178) * record: Check for overflow in RecordSanityCheckRegisterClients() (CVE-2025-49179) * randr: Check for overflow in RRChangeProviderProperty() (CVE-2025-49180) * xfree86: Check for RandR provider functions (CVE-2025-49180) * os: Check for integer overflow on BigRequest length (CVE-2025-49176) Checksums-Sha1: 2491a27d26eeb93c49c8f102bec36bff1d337279 2742880 xnest-dbgsym_21.1.7-3+deb12u10_mips64el.deb 635ab2d2d9e5507c0b4fbac1664971eb216a9fee 2936592 xnest_21.1.7-3+deb12u10_mips64el.deb b8562e7bb7b18343d3b7eb487e04ac8162b2f2ea 14756 xorg-server_21.1.7-3+deb12u10_mips64el-buildd.buildinfo b843ff4c9c7e5f4c16c3085ef3b9de4d1a50212e 4031460 xserver-xephyr-dbgsym_21.1.7-3+deb12u10_mips64el.deb 296cfa8ee9325266f9f4f277863efbf17437acd8 3177544 xserver-xephyr_21.1.7-3+deb12u10_mips64el.deb 8a4749129fcc552533c34a2b540094f85ec4cb63 5886788 xserver-xorg-core-dbgsym_21.1.7-3+deb12u10_mips64el.deb ff721780927dbc4193e4d2836804a3c4714f97ba 840932 xserver-xorg-core-udeb_21.1.7-3+deb12u10_mips64el.udeb 111a9adf0cca7cb711378aaf10fffa0d4decda85 3546904 xserver-xorg-core_21.1.7-3+deb12u10_mips64el.deb 1ecca2551c8d1b659abc7f9e91a37f60136caf77 2554684 xserver-xorg-dev_21.1.7-3+deb12u10_mips64el.deb e006ed7662deeb4722f0e0e476c81065028e9e45 9712 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u10_mips64el.deb aa6286d36a14f2995fd2b53d833e9f28b479ffc6 2388940 xserver-xorg-legacy_21.1.7-3+deb12u10_mips64el.deb 77721ffb0d7eebbe65443361b18af23a69bb1e29 3340372 xvfb-dbgsym_21.1.7-3+deb12u10_mips64el.deb cdcbddb57a6fee3feaa7bc154bdedf4a58d82772 3057808 xvfb_21.1.7-3+deb12u10_mips64el.deb Checksums-Sha256: 61532f9606ab2e7deba2b4ea7f3749c3713ad24b13c335d56e0aa8f35e10de7f 2742880 xnest-dbgsym_21.1.7-3+deb12u10_mips64el.deb 693b8b91ff7612c86b64324e264dc51a1ad36a8e472915d23bba639acc75c9d6 2936592 xnest_21.1.7-3+deb12u10_mips64el.deb d3e121036221a46adadaf7df6886d8a08255fe08f7ef7af9e029b8d03f92b9e5 14756 xorg-server_21.1.7-3+deb12u10_mips64el-buildd.buildinfo bb35a5eef3b581899a87a141282bacdbea2f243fe7ffa10e7be7653bf2cb2259 4031460 xserver-xephyr-dbgsym_21.1.7-3+deb12u10_mips64el.deb 2c8ac50300e117ee4a9a10ae6bc178c0e23639cdb440552142d744aadf0e1e5a 3177544 xserver-xephyr_21.1.7-3+deb12u10_mips64el.deb 0030bea9fd68690e6b44af1f782f5200e2a4f078d31df81b62d20f74e1f2e893 5886788 xserver-xorg-core-dbgsym_21.1.7-3+deb12u10_mips64el.deb 9b3924eb7bca7d4c6c703997844dcc698e7fbe62018a4ea8845f3b68798863b2 840932 xserver-xorg-core-udeb_21.1.7-3+deb12u10_mips64el.udeb a0af0ef42d776b40265713f96b81d3b75b4d2c549ae92b83572ebda70061eb4b 3546904 xserver-xorg-core_21.1.7-3+deb12u10_mips64el.deb cab62e79523defc7c6a42e50aef469e8ab438ea95f02ad7eec6e02fe5616b7ed 2554684 xserver-xorg-dev_21.1.7-3+deb12u10_mips64el.deb 938ac80fd29a51712ca05e3784fd905e2f11f1420fd40af215d7031660283dcc 9712 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u10_mips64el.deb 0a43c0b004b6c9e8c10e6aab1fffde1bcdcb24d36e70ecf8ccd72357d2ce26b8 2388940 xserver-xorg-legacy_21.1.7-3+deb12u10_mips64el.deb 5fc3f0d841a803fc2ed5d4dea1efbc7f1d1a216312122ea21746eeb5a8908847 3340372 xvfb-dbgsym_21.1.7-3+deb12u10_mips64el.deb 841a5039366ad549ce51173f84ae9730be6fc7ba08d69a7e1f9729122edf69b4 3057808 xvfb_21.1.7-3+deb12u10_mips64el.deb Files: 18b2d0f2d703eee14f8f1b9d1e59aec0 2742880 debug optional xnest-dbgsym_21.1.7-3+deb12u10_mips64el.deb f5e5a5926fd909e220f0454bab3873bb 2936592 x11 optional xnest_21.1.7-3+deb12u10_mips64el.deb 81bdd721764f1485e0a646b458e738fc 14756 x11 optional xorg-server_21.1.7-3+deb12u10_mips64el-buildd.buildinfo 678411aa75a154c8c9927bf20ae23b5d 4031460 debug optional xserver-xephyr-dbgsym_21.1.7-3+deb12u10_mips64el.deb 583213d46fd1c9d4f6774febd3e6b9ab 3177544 x11 optional xserver-xephyr_21.1.7-3+deb12u10_mips64el.deb 7f4aff56180201fa78f7164a00855a29 5886788 debug optional xserver-xorg-core-dbgsym_21.1.7-3+deb12u10_mips64el.deb 0200f0e294b33b574b0a88be52be2348 840932 debian-installer optional xserver-xorg-core-udeb_21.1.7-3+deb12u10_mips64el.udeb b8cb3e28319f98fc42846234248c7895 3546904 x11 optional xserver-xorg-core_21.1.7-3+deb12u10_mips64el.deb 2a109d68ced4ac699e5c2a303bfbccb8 2554684 x11 optional xserver-xorg-dev_21.1.7-3+deb12u10_mips64el.deb 2f76323e59370c6e2af1b87faacccc20 9712 debug optional xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u10_mips64el.deb 839b6976b44c6e4ed4d34459be82418a 2388940 x11 optional xserver-xorg-legacy_21.1.7-3+deb12u10_mips64el.deb e4d094cb6cb599bedd8a088b23cd6bea 3340372 debug optional xvfb-dbgsym_21.1.7-3+deb12u10_mips64el.deb 63aa826e0e7c339bf037258622ef201c 3057808 x11 optional xvfb_21.1.7-3+deb12u10_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEesE3YcWKZXIkRPMemf85J+x5/aoFAmhVeeoACgkQmf85J+x5 /arHLg/9H+9YGL7MwukQGAkCMULojbf+DR+KvSNkaoGa9omlDtp42soeNGlPQPDH ygrum9FdHeM10kuMHTIEE2FzxBvi4kMeblEY/DqO3068pkVonLcA156z5TDHAv1X wH+FgSYUhn98gDkpLvbGGaq1o/B5uGwx4QkBgsgTq97UEWu7cjqmtwSPFRzm7ofI FljjWsr3WGj7aObojEzLm6miy6aq7XN8gB95p6hRNatmfNcfnfSFd0v/56v2ftKC +ki6D5hEIciB/L2q8arpV70ZhPYp309JaHzv84Nf0SCUR6zErtyLoT1IIjMRwCdg IyeYdWdG5rmIj2N/576h5u7OXpVPOr+b1TGjK0s0wM/UBTrFrDJE2LE9Nu9wjz57 yL+/iod+UZzrF79ksFsY7+bJSf1IzZG7uUHJhagEJQlHXJbvLaWgnVA8hiz8MtJk SVCkdCInuWZ7/mIYNB2xqoJZdDjj5fAqDXTO3GbTsOTc4PU7NdiifXdphYa2jXAn NZj6fxwWmFfSMPWQwI3LAmnWiexaIz6dJBhU/wgSLHUTWPfO2w7hTPRUKTXm+WpJ J2qjR9GRbGkZ7Uu6fryfdtCgMTikOStsHfGqwX9pZRG6ta40/Uqq+/B6aeszexlN b7d26GsOrDyuOuq3AEAaq0swLeCkA0vq7I27OeDx5u0luBnuPfU= =dwUt -----END PGP SIGNATURE-----