-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 20 Jun 2025 14:46:37 +0200 Source: xorg-server Binary: xnest xnest-dbgsym xserver-xephyr xserver-xephyr-dbgsym xserver-xorg-core xserver-xorg-core-dbgsym xserver-xorg-core-udeb xserver-xorg-dev xserver-xorg-legacy xserver-xorg-legacy-dbgsym xvfb xvfb-dbgsym Architecture: ppc64el Version: 2:21.1.7-3+deb12u10 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Salvatore Bonaccorso Description: xnest - Nested X server xserver-xephyr - nested X server xserver-xorg-core - Xorg X server - core server xserver-xorg-core-udeb - Xorg X server - core server (udeb) xserver-xorg-dev - Xorg X server - development files xserver-xorg-legacy - setuid root Xorg server wrapper xvfb - Virtual Framebuffer 'fake' X server Changes: xorg-server (2:21.1.7-3+deb12u10) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * render: Avoid 0 or less animated cursors (CVE-2025-49175) * os: Do not overflow the integer size with BigRequest (CVE-2025-49176) * xfixes: Check request length for SetClientDisconnectMode (CVE-2025-49177) * os: Account for bytes to ignore when sharing input buffer (CVE-2025-49178) * record: Check for overflow in RecordSanityCheckRegisterClients() (CVE-2025-49179) * randr: Check for overflow in RRChangeProviderProperty() (CVE-2025-49180) * xfree86: Check for RandR provider functions (CVE-2025-49180) * os: Check for integer overflow on BigRequest length (CVE-2025-49176) Checksums-Sha1: a22e4049900d9dca8425dadee1a3a0aaa002513c 2724864 xnest-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 06c4c79ca91959c9e1fc185ad81364e9c46b5355 3082932 xnest_21.1.7-3+deb12u10_ppc64el.deb 56c3b493b8b248f772fffa278ad63ffa93882f74 14937 xorg-server_21.1.7-3+deb12u10_ppc64el-buildd.buildinfo 32c33285482024d003f82206b1397e552ffd9a3d 3983944 xserver-xephyr-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 96029f97b767702194345217aef1b2477f209827 3380736 xserver-xephyr_21.1.7-3+deb12u10_ppc64el.deb 167a2c27b73771fc74d48680311520fdf0322ead 5800688 xserver-xorg-core-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 069982ac988fc47dcdc697e0caed6f4fb4e4f6fa 1042772 xserver-xorg-core-udeb_21.1.7-3+deb12u10_ppc64el.udeb f0528c492bcfe8d0feda1835b745afe2c9e13754 3825048 xserver-xorg-core_21.1.7-3+deb12u10_ppc64el.deb 61c7d71953d555e8e9ecd69f393c32e12067252a 2554676 xserver-xorg-dev_21.1.7-3+deb12u10_ppc64el.deb a8a86975a24e473ebb189f4f9e511f6c69a7baff 9732 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u10_ppc64el.deb de10da3d3d766c5fd8cdfc72ee7e7e07f5fa2685 2389480 xserver-xorg-legacy_21.1.7-3+deb12u10_ppc64el.deb d3a6af66fe76a4451c57f0b18019572bca66edf1 3301792 xvfb-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 0118ab141de15c4d41333b5f71ea583ea4631ff9 3235260 xvfb_21.1.7-3+deb12u10_ppc64el.deb Checksums-Sha256: 67f71393801632dcd22637ceddc3b75cad39f42d26e3fe19a58bb4a77cc66ed1 2724864 xnest-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 4199c2ca6d30947208529d2a6cf12fef45c94881e38c78402b8d93f71281cbc3 3082932 xnest_21.1.7-3+deb12u10_ppc64el.deb 0f7c6aceaa7368d16a8d9ce999fc10113819e8304e650c514f7c4d9e24130aa9 14937 xorg-server_21.1.7-3+deb12u10_ppc64el-buildd.buildinfo 3ffb8ac9b952f570d15c6f39d72c428eb93c6d1f1afe2caa779903228a2fbc7d 3983944 xserver-xephyr-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 0bb84839b021d45d029c651703a43ad3e8033c4c5d9f560a46f65f118c9ddea7 3380736 xserver-xephyr_21.1.7-3+deb12u10_ppc64el.deb 43f13a3fe8ab2beab20a560510e7e0bb403cf87e734ca189d95f9d4e2c48c9de 5800688 xserver-xorg-core-dbgsym_21.1.7-3+deb12u10_ppc64el.deb a5bf9fb4e85d3506d9a68bc6c574d2678e15be106d91430b80765edf2fe1da4a 1042772 xserver-xorg-core-udeb_21.1.7-3+deb12u10_ppc64el.udeb 02db251ccd1137ff223eb82494e738729da78a2a2bbc41385f7dc49c2bca40e3 3825048 xserver-xorg-core_21.1.7-3+deb12u10_ppc64el.deb ce8f654b022ead607d59d86c375e87160794288c9aad381e345734518dc168d3 2554676 xserver-xorg-dev_21.1.7-3+deb12u10_ppc64el.deb c7a447297d6f723c5ba3d6b8ed62d50c6b7faafb39fe548626a51fd48544a39e 9732 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 34639dc88f3c30c408c3afbc0f2a9a84f10db5616bf3747b4ba4a11d8c6227a7 2389480 xserver-xorg-legacy_21.1.7-3+deb12u10_ppc64el.deb cfee2723ed55cff0a6b2cddc35b4aab1d744b8f6521249a97faf41295c59bea6 3301792 xvfb-dbgsym_21.1.7-3+deb12u10_ppc64el.deb f1f01c2136dfa25b56de4eee8de2788b7258f6b21ccc8df2ba0f728ecbe35f70 3235260 xvfb_21.1.7-3+deb12u10_ppc64el.deb Files: be918b28de380f71f0d7e1a420c347c9 2724864 debug optional xnest-dbgsym_21.1.7-3+deb12u10_ppc64el.deb a235f2b09a867c12f8909b4ab81878ca 3082932 x11 optional xnest_21.1.7-3+deb12u10_ppc64el.deb 5b26c55fb094affa00bd199b2dfb94c1 14937 x11 optional xorg-server_21.1.7-3+deb12u10_ppc64el-buildd.buildinfo 5c1f569d7525abc47ae3b424ce00a790 3983944 debug optional xserver-xephyr-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 8d8e630322844adbd9f92418fa0d0aec 3380736 x11 optional xserver-xephyr_21.1.7-3+deb12u10_ppc64el.deb fe3fb5ab284ca34a3abccaa7d5b9c8f4 5800688 debug optional xserver-xorg-core-dbgsym_21.1.7-3+deb12u10_ppc64el.deb d0cfa841baf44c2e6cd1e5bc3e6fcf21 1042772 debian-installer optional xserver-xorg-core-udeb_21.1.7-3+deb12u10_ppc64el.udeb 7572de2ddccea0cea6d06c88eeb00e36 3825048 x11 optional xserver-xorg-core_21.1.7-3+deb12u10_ppc64el.deb 978683fed9ee75b10237fa8df49fd3be 2554676 x11 optional xserver-xorg-dev_21.1.7-3+deb12u10_ppc64el.deb f530cddb744f61fc216a793f22f803fb 9732 debug optional xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 5b6541425ee9c37f3eb8288c3ff28617 2389480 x11 optional xserver-xorg-legacy_21.1.7-3+deb12u10_ppc64el.deb a50e26b8f743df5612a1b1e06da20b9f 3301792 debug optional xvfb-dbgsym_21.1.7-3+deb12u10_ppc64el.deb 466c5f97d151d670c63fd85231485a56 3235260 x11 optional xvfb_21.1.7-3+deb12u10_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYo4fOZBRi9qmvTxH1PowSTJ8+YQFAmhVeEwACgkQ1PowSTJ8 +YSA0A/9Hig8CVmT9mahX2a1v0SN+8m60cBbSyVUz9PKgTqCQQwW4D/UVSH4U+A8 No0HoQWvNpm9qsKr0acuPBDS0/AdDjbVsI/ES//2ys2QxWhdxGuqNGwsKKGqRnRW VK/ELqoBXubtDRqvwJO1l5vLele+RWvQofAv6JW/p+YV6ySe00PC69HcUx4qZs+A lKBlXKA3an6rzPxCbbgY0PPZzJby1APfbHk1njFxR65tN98N8MNhO4hGYp92Rn4K MHv6Wwmva2+59dzxW78d8HbgWfDidkSS5fzG9N4sFLSWFZ5NT4tlxyf39CcVyBS/ 186xdBVWaEeaEUpANHOb5j8HYERZatRduF0KBCHEBBAywHSJka/CnDQ9SFtKiEKn LsKvBbYyvG+ZE+jf1pvQHMVBX5BhwxAO27UBKBm55xdOZ82Wwoi2OqjD4dvRrl4B O2k/XDvF6MYlyR1fHCkQUfmyuKs9JP9xUhZEKjgP2oHfZ7Bg+GmWlSuqFda0ruTc Zd8FJVDqK+173GCTRxY+KnQ7YO7zR3m8Loq00YXqpzFpHWc56VF6HeG8SEHT7mVt E3ADVuk6DdN/1SaZ3nd+A14x96s0xuYWL7phANsbN48Kln+Sez2bEWF4CqfrWi6d kKBXDlaVE/cPX/ar5Mf43APelQEwQ31FnSWOaXzOzYGzkkcfT84= =Pruk -----END PGP SIGNATURE-----