From 8df6b161fe27f3a5c63320f009d7bd701b3b8061 Mon Sep 17 00:00:00 2001 From: Jan Grulich Date: Fri, 7 Mar 2025 14:20:05 +0100 Subject: [PATCH] 1.15.0 Resolves: RHEL-78617 Add SELinux policy rules allowing to access /proc/sys/fs/nr_open Resolves: RHEL-77973 Add SELinux policy rules allowing to create directories under /root Resolves: RHEL-77975 Fix CVE-2025-26594 xorg-x11-server Use-after-free of the root cursor Resolves: RHEL-80208 Fix CVE-2025-26595 xorg-x11-server Buffer overflow in XkbVModMaskText() Resolves: RHEL-80189 Fix CVE-2025-26596 xorg-x11-server Heap overflow in XkbWriteKeySyms() Resolves: RHEL-80194 Fix CVE-2025-26597 xorg-x11-server Buffer overflow in XkbChangeTypesOfKey() Resolves: RHEL-80196 Fix CVE-2025-26598 xorg-x11-server Out-of-bounds write in CreatePointerBarrierClient() Resolves: RHEL-80197 Fix CVE-2025-26599 xorg-x11-server Use of uninitialized pointer in compRedirectWindow() Resolves: RHEL-80206 Fix CVE-2025-26600 xorg-x11-server Use-after-free in PlayReleasedEvents() Resolves: RHEL-80205 Fix CVE-2025-26601 xorg-x11-server Use-after-free in SyncInitTrigger() Resolves: RHEL-80209 --- .gitignore | 1 + sources | 2 +- ...add-clipboard-support-to-x0vncserver.patch | 543 ------------------ ...-to-connect-only-user-owning-session.patch | 26 +- ...lowing-access-to-proc-sys-fs-nr-open.patch | 27 + ...-allowing-create-dirs-under-root-dir.patch | 47 ++ ...c-avoid-invalid-xfree-for-xclasshint.patch | 24 - ...el-window-setup-for-selection-window.patch | 22 - ...pointer-position-for-floating-device.patch | 13 - ...e-existing-log-to-log-old-if-present.patch | 94 --- tigervnc.spec | 67 ++- 11 files changed, 131 insertions(+), 735 deletions(-) delete mode 100644 tigervnc-add-clipboard-support-to-x0vncserver.patch create mode 100644 tigervnc-add-selinux-policy-rules-allowing-access-to-proc-sys-fs-nr-open.patch create mode 100644 tigervnc-add-selinux-policy-rules-allowing-create-dirs-under-root-dir.patch delete mode 100644 tigervnc-avoid-invalid-xfree-for-xclasshint.patch delete mode 100644 tigervnc-do-proper-toplevel-window-setup-for-selection-window.patch delete mode 100644 tigervnc-dont-get-pointer-position-for-floating-device.patch delete mode 100644 tigervnc-vncsession-move-existing-log-to-log-old-if-present.patch diff --git a/.gitignore b/.gitignore index 09406a5..0e92072 100644 --- a/.gitignore +++ b/.gitignore @@ -34,3 +34,4 @@ tigervnc-1.0.90-20100721svn4113.tar.bz2 /tigervnc-1.13.1.tar.gz /tigervnc-1.14.0.tar.gz /tigervnc-1.14.1.tar.gz +/tigervnc-1.15.0.tar.gz diff --git a/sources b/sources index 0b7e3fd..eaa4b26 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (tigervnc-1.14.1.tar.gz) = d7a6cff4a3a1e4c30e2dbd6e17ad2d76145e76f5c1a93abbaf32b1c488377a4eaf936d4e8a24a97863948138ba40031c862f9da1c1cd427da35ebffa8eaa4f31 +SHA512 (tigervnc-1.15.0.tar.gz) = 0b550296b5bd06ac9d63ce10861ff54d24e79b6ac1551d80e9b81845fa873d85bfd684112c66d86188c9c61fdffb9421ea8696c1c7fd15a24fb1bf6bfe6a5e05 diff --git a/tigervnc-add-clipboard-support-to-x0vncserver.patch b/tigervnc-add-clipboard-support-to-x0vncserver.patch deleted file mode 100644 index 671b798..0000000 --- a/tigervnc-add-clipboard-support-to-x0vncserver.patch +++ /dev/null @@ -1,543 +0,0 @@ -From c23be952f50ba34c49134b6280ce503f154dc9bc Mon Sep 17 00:00:00 2001 -From: Gaurav Ujjwal -Date: Wed, 25 Sep 2024 21:21:26 +0530 -Subject: [PATCH] Add clipboard support to x0vncserver - ---- - unix/tx/TXWindow.cxx | 13 ++- - unix/tx/TXWindow.h | 3 +- - unix/x0vncserver/CMakeLists.txt | 1 + - unix/x0vncserver/XDesktop.cxx | 49 +++++++- - unix/x0vncserver/XDesktop.h | 13 ++- - unix/x0vncserver/XSelection.cxx | 195 +++++++++++++++++++++++++++++++ - unix/x0vncserver/XSelection.h | 58 +++++++++ - unix/x0vncserver/x0vncserver.cxx | 5 - - unix/x0vncserver/x0vncserver.man | 21 ++++ - 9 files changed, 344 insertions(+), 14 deletions(-) - create mode 100644 unix/x0vncserver/XSelection.cxx - create mode 100644 unix/x0vncserver/XSelection.h - -diff --git a/unix/tx/TXWindow.cxx b/unix/tx/TXWindow.cxx -index ee097e4..b10ed84 100644 ---- a/unix/tx/TXWindow.cxx -+++ b/unix/tx/TXWindow.cxx -@@ -36,7 +36,7 @@ std::list windows; - - Atom wmProtocols, wmDeleteWindow, wmTakeFocus; - Atom xaTIMESTAMP, xaTARGETS, xaSELECTION_TIME, xaSELECTION_STRING; --Atom xaCLIPBOARD; -+Atom xaCLIPBOARD, xaUTF8_STRING, xaINCR; - unsigned long TXWindow::black, TXWindow::white; - unsigned long TXWindow::defaultFg, TXWindow::defaultBg; - unsigned long TXWindow::lightBg, TXWindow::darkBg; -@@ -65,6 +65,8 @@ void TXWindow::init(Display* dpy, const char* defaultWindowClass_) - xaSELECTION_TIME = XInternAtom(dpy, "SELECTION_TIME", False); - xaSELECTION_STRING = XInternAtom(dpy, "SELECTION_STRING", False); - xaCLIPBOARD = XInternAtom(dpy, "CLIPBOARD", False); -+ xaUTF8_STRING = XInternAtom(dpy, "UTF8_STRING", False); -+ xaINCR = XInternAtom(dpy, "INCR", False); - XColor cols[6]; - cols[0].red = cols[0].green = cols[0].blue = 0x0000; - cols[1].red = cols[1].green = cols[1].blue = 0xbbbb; -@@ -462,17 +464,18 @@ void TXWindow::handleXEvent(XEvent* ev) - } else { - se.property = ev->xselectionrequest.property; - if (se.target == xaTARGETS) { -- Atom targets[2]; -+ Atom targets[3]; - targets[0] = xaTIMESTAMP; - targets[1] = XA_STRING; -+ targets[2] = xaUTF8_STRING; - XChangeProperty(dpy, se.requestor, se.property, XA_ATOM, 32, -- PropModeReplace, (unsigned char*)targets, 2); -+ PropModeReplace, (unsigned char*)targets, 3); - } else if (se.target == xaTIMESTAMP) { - Time t = selectionOwnTime[se.selection]; - XChangeProperty(dpy, se.requestor, se.property, XA_INTEGER, 32, - PropModeReplace, (unsigned char*)&t, 1); -- } else if (se.target == XA_STRING) { -- if (!selectionRequest(se.requestor, se.selection, se.property)) -+ } else if (se.target == XA_STRING || se.target == xaUTF8_STRING) { -+ if (!selectionRequest(se.requestor, se.selection, se.target, se.property)) - se.property = None; - } else { - se.property = None; -diff --git a/unix/tx/TXWindow.h b/unix/tx/TXWindow.h -index 223c07a..32ae9a3 100644 ---- a/unix/tx/TXWindow.h -+++ b/unix/tx/TXWindow.h -@@ -155,6 +155,7 @@ public: - // returning true if successful, false otherwise. - virtual bool selectionRequest(Window /*requestor*/, - Atom /*selection*/, -+ Atom /*target*/, - Atom /*property*/) { return false;} - - // Static methods -@@ -224,6 +225,6 @@ private: - - extern Atom wmProtocols, wmDeleteWindow, wmTakeFocus; - extern Atom xaTIMESTAMP, xaTARGETS, xaSELECTION_TIME, xaSELECTION_STRING; --extern Atom xaCLIPBOARD; -+extern Atom xaCLIPBOARD, xaUTF8_STRING, xaINCR; - - #endif -diff --git a/unix/x0vncserver/CMakeLists.txt b/unix/x0vncserver/CMakeLists.txt -index 5ce9577..9d6d213 100644 ---- a/unix/x0vncserver/CMakeLists.txt -+++ b/unix/x0vncserver/CMakeLists.txt -@@ -11,6 +11,7 @@ add_executable(x0vncserver - XPixelBuffer.cxx - XDesktop.cxx - RandrGlue.c -+ XSelection.cxx - ../vncconfig/QueryConnectDialog.cxx - ) - -diff --git a/unix/x0vncserver/XDesktop.cxx b/unix/x0vncserver/XDesktop.cxx -index 1e52987..db5b6ae 100644 ---- a/unix/x0vncserver/XDesktop.cxx -+++ b/unix/x0vncserver/XDesktop.cxx -@@ -43,6 +43,7 @@ - #endif - #ifdef HAVE_XFIXES - #include -+#include - #endif - #ifdef HAVE_XRANDR - #include -@@ -81,7 +82,7 @@ static const char * ledNames[XDESKTOP_N_LEDS] = { - - XDesktop::XDesktop(Display* dpy_, Geometry *geometry_) - : dpy(dpy_), geometry(geometry_), pb(0), server(0), -- queryConnectDialog(0), queryConnectSock(0), -+ queryConnectDialog(0), queryConnectSock(0), selection(dpy_, this), - oldButtonMask(0), haveXtest(false), haveDamage(false), - maxButtons(0), running(false), ledMasks(), ledState(0), - codeMap(0), codeMapLen(0) -@@ -179,10 +180,15 @@ XDesktop::XDesktop(Display* dpy_, Geometry *geometry_) - if (XFixesQueryExtension(dpy, &xfixesEventBase, &xfixesErrorBase)) { - XFixesSelectCursorInput(dpy, DefaultRootWindow(dpy), - XFixesDisplayCursorNotifyMask); -+ -+ XFixesSelectSelectionInput(dpy, DefaultRootWindow(dpy), XA_PRIMARY, -+ XFixesSetSelectionOwnerNotifyMask); -+ XFixesSelectSelectionInput(dpy, DefaultRootWindow(dpy), xaCLIPBOARD, -+ XFixesSetSelectionOwnerNotifyMask); - } else { - #endif - vlog.info("XFIXES extension not present"); -- vlog.info("Will not be able to display cursors"); -+ vlog.info("Will not be able to display cursors or monitor clipboard"); - #ifdef HAVE_XFIXES - } - #endif -@@ -892,6 +898,20 @@ bool XDesktop::handleGlobalEvent(XEvent* ev) { - return false; - - return setCursor(); -+ } -+ else if (ev->type == xfixesEventBase + XFixesSelectionNotify) { -+ XFixesSelectionNotifyEvent* sev = (XFixesSelectionNotifyEvent*)ev; -+ -+ if (!running) -+ return true; -+ -+ if (sev->subtype != XFixesSetSelectionOwnerNotify) -+ return false; -+ -+ selection.handleSelectionOwnerChange(sev->owner, sev->selection, -+ sev->timestamp); -+ -+ return true; - #endif - #ifdef HAVE_XRANDR - } else if (ev->type == Expose) { -@@ -1039,3 +1059,28 @@ bool XDesktop::setCursor() - return true; - } - #endif -+ -+// X selection availability changed, let VNC clients know -+void XDesktop::handleXSelectionAnnounce(bool available) { -+ server->announceClipboard(available); -+} -+ -+// A VNC client wants data, send request to selection owner -+void XDesktop::handleClipboardRequest() { -+ selection.requestSelectionData(); -+} -+ -+// Data is available, send it to clients -+void XDesktop::handleXSelectionData(const char* data) { -+ server->sendClipboardData(data); -+} -+ -+// When a client says it has clipboard data, request it -+void XDesktop::handleClipboardAnnounce(bool available) { -+ if(available) server->requestClipboard(); -+} -+ -+// Client has sent the data -+void XDesktop::handleClipboardData(const char* data) { -+ if (data) selection.handleClientClipboardData(data); -+} -diff --git a/unix/x0vncserver/XDesktop.h b/unix/x0vncserver/XDesktop.h -index 4777a65..bc8d2a9 100644 ---- a/unix/x0vncserver/XDesktop.h -+++ b/unix/x0vncserver/XDesktop.h -@@ -32,6 +32,8 @@ - - #include - -+#include "XSelection.h" -+ - class Geometry; - class XPixelBuffer; - -@@ -46,7 +48,8 @@ struct AddedKeySym - - class XDesktop : public rfb::SDesktop, - public TXGlobalEventHandler, -- public QueryResultCallback -+ public QueryResultCallback, -+ public XSelectionHandler - { - public: - XDesktop(Display* dpy_, Geometry *geometry); -@@ -65,6 +68,13 @@ public: - virtual void clientCutText(const char* str); - virtual unsigned int setScreenLayout(int fb_width, int fb_height, - const rfb::ScreenSet& layout); -+ void handleClipboardRequest() override; -+ void handleClipboardAnnounce(bool available) override; -+ void handleClipboardData(const char* data) override; -+ -+ // -=- XSelectionHandler interface -+ void handleXSelectionAnnounce(bool available) override; -+ void handleXSelectionData(const char* data) override; - - // -=- TXGlobalEventHandler interface - virtual bool handleGlobalEvent(XEvent* ev); -@@ -80,6 +90,7 @@ protected: - rfb::VNCServer* server; - QueryConnectDialog* queryConnectDialog; - network::Socket* queryConnectSock; -+ XSelection selection; - int oldButtonMask; - bool haveXtest; - bool haveDamage; -diff --git a/unix/x0vncserver/XSelection.cxx b/unix/x0vncserver/XSelection.cxx -new file mode 100644 -index 0000000..72dd537 ---- /dev/null -+++ b/unix/x0vncserver/XSelection.cxx -@@ -0,0 +1,195 @@ -+/* Copyright (C) 2024 Gaurav Ujjwal. All Rights Reserved. -+ * -+ * This is free software; you can redistribute it and/or modify -+ * it under the terms of the GNU General Public License as published by -+ * the Free Software Foundation; either version 2 of the License, or -+ * (at your option) any later version. -+ * -+ * This software is distributed in the hope that it will be useful, -+ * but WITHOUT ANY WARRANTY; without even the implied warranty of -+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+ * GNU General Public License for more details. -+ * -+ * You should have received a copy of the GNU General Public License -+ * along with this software; if not, write to the Free Software -+ * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, -+ * USA. -+ */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+rfb::BoolParameter setPrimary("SetPrimary", -+ "Set the PRIMARY as well as the CLIPBOARD selection", -+ true); -+rfb::BoolParameter sendPrimary("SendPrimary", -+ "Send the PRIMARY as well as the CLIPBOARD selection", -+ true); -+ -+static rfb::LogWriter vlog("XSelection"); -+ -+XSelection::XSelection(Display* dpy_, XSelectionHandler* handler_) -+ : TXWindow(dpy_, 1, 1, nullptr), handler(handler_), announcedSelection(None) -+{ -+ probeProperty = XInternAtom(dpy, "TigerVNC_ProbeProperty", False); -+ transferProperty = XInternAtom(dpy, "TigerVNC_TransferProperty", False); -+ timestampProperty = XInternAtom(dpy, "TigerVNC_TimestampProperty", False); -+ setName("TigerVNC Clipboard (x0vncserver)"); -+ addEventMask(PropertyChangeMask); // Required for PropertyNotify events -+} -+ -+static Bool PropertyEventMatcher(Display* /* dpy */, XEvent* ev, XPointer prop) -+{ -+ if (ev->type == PropertyNotify && ev->xproperty.atom == *((Atom*)prop)) -+ return True; -+ else -+ return False; -+} -+ -+Time XSelection::getXServerTime() -+{ -+ XEvent ev; -+ uint8_t data = 0; -+ -+ // Trigger a PropertyNotify event to extract server time -+ XChangeProperty(dpy, win(), timestampProperty, XA_STRING, 8, PropModeReplace, -+ &data, sizeof(data)); -+ XIfEvent(dpy, &ev, &PropertyEventMatcher, (XPointer)×tampProperty); -+ return ev.xproperty.time; -+} -+ -+// Takes ownership of selections, backed by given data. -+void XSelection::handleClientClipboardData(const char* data) -+{ -+ vlog.debug("Received client clipboard data, taking selection ownership"); -+ -+ Time time = getXServerTime(); -+ ownSelection(xaCLIPBOARD, time); -+ if (!selectionOwner(xaCLIPBOARD)) -+ vlog.error("Unable to own CLIPBOARD selection"); -+ -+ if (setPrimary) { -+ ownSelection(XA_PRIMARY, time); -+ if (!selectionOwner(XA_PRIMARY)) -+ vlog.error("Unable to own PRIMARY selection"); -+ } -+ -+ if (selectionOwner(xaCLIPBOARD) || selectionOwner(XA_PRIMARY)) -+ clientData = data; -+} -+ -+// We own the selection and another X app has asked for data -+bool XSelection::selectionRequest(Window requestor, Atom selection, Atom target, -+ Atom property) -+{ -+ if (clientData.empty() || requestor == win() || !selectionOwner(selection)) -+ return false; -+ -+ if (target == XA_STRING) { -+ std::string latin1 = rfb::utf8ToLatin1(clientData.data(), clientData.length()); -+ XChangeProperty(dpy, requestor, property, XA_STRING, 8, PropModeReplace, -+ (unsigned char*)latin1.data(), latin1.length()); -+ return true; -+ } -+ -+ if (target == xaUTF8_STRING) { -+ XChangeProperty(dpy, requestor, property, xaUTF8_STRING, 8, PropModeReplace, -+ (unsigned char*)clientData.data(), clientData.length()); -+ return true; -+ } -+ -+ return false; -+} -+ -+// Selection-owner change implies a change in selection data. -+void XSelection::handleSelectionOwnerChange(Window owner, Atom selection, Time time) -+{ -+ if (selection != XA_PRIMARY && selection != xaCLIPBOARD) -+ return; -+ if (selection == XA_PRIMARY && !sendPrimary) -+ return; -+ -+ if (selection == announcedSelection) -+ announceSelection(None); -+ -+ if (owner == None || owner == win()) -+ return; -+ -+ if (!selectionOwner(XA_PRIMARY) && !selectionOwner(xaCLIPBOARD)) -+ clientData = ""; -+ -+ XConvertSelection(dpy, selection, xaTARGETS, probeProperty, win(), time); -+} -+ -+void XSelection::announceSelection(Atom selection) -+{ -+ announcedSelection = selection; -+ handler->handleXSelectionAnnounce(selection != None); -+} -+ -+void XSelection::requestSelectionData() -+{ -+ if (announcedSelection != None) -+ XConvertSelection(dpy, announcedSelection, xaTARGETS, transferProperty, win(), -+ CurrentTime); -+} -+ -+// Some information about selection is received from current owner -+void XSelection::selectionNotify(XSelectionEvent* ev, Atom type, int format, -+ int nitems, void* data) -+{ -+ if (!ev || !data || type == None) -+ return; -+ -+ if (ev->target == xaTARGETS) { -+ if (format != 32 || type != XA_ATOM) -+ return; -+ -+ Atom* targets = (Atom*)data; -+ bool utf8Supported = false; -+ bool stringSupported = false; -+ -+ for (int i = 0; i < nitems; i++) { -+ if (targets[i] == xaUTF8_STRING) -+ utf8Supported = true; -+ else if (targets[i] == XA_STRING) -+ stringSupported = true; -+ } -+ -+ if (ev->property == probeProperty) { -+ // Only probing for now, will issue real request when client asks for data -+ if (stringSupported || utf8Supported) -+ announceSelection(ev->selection); -+ return; -+ } -+ -+ // Prefer UTF-8 if available -+ if (utf8Supported) -+ XConvertSelection(dpy, ev->selection, xaUTF8_STRING, transferProperty, win(), -+ ev->time); -+ else if (stringSupported) -+ XConvertSelection(dpy, ev->selection, XA_STRING, transferProperty, win(), -+ ev->time); -+ } else if (ev->target == xaUTF8_STRING || ev->target == XA_STRING) { -+ if (type == xaINCR) { -+ // Incremental transfer is not supported -+ vlog.debug("Selected data is too big!"); -+ return; -+ } -+ -+ if (format != 8) -+ return; -+ -+ if (type == xaUTF8_STRING) { -+ std::string result = rfb::convertLF((char*)data, nitems); -+ handler->handleXSelectionData(result.c_str()); -+ } else if (type == XA_STRING) { -+ std::string result = rfb::convertLF((char*)data, nitems); -+ result = rfb::latin1ToUTF8(result.data(), result.length()); -+ handler->handleXSelectionData(result.c_str()); -+ } -+ } -+} -\ No newline at end of file -diff --git a/unix/x0vncserver/XSelection.h b/unix/x0vncserver/XSelection.h -new file mode 100644 -index 0000000..fbe1f29 ---- /dev/null -+++ b/unix/x0vncserver/XSelection.h -@@ -0,0 +1,58 @@ -+/* Copyright (C) 2024 Gaurav Ujjwal. All Rights Reserved. -+ * -+ * This is free software; you can redistribute it and/or modify -+ * it under the terms of the GNU General Public License as published by -+ * the Free Software Foundation; either version 2 of the License, or -+ * (at your option) any later version. -+ * -+ * This software is distributed in the hope that it will be useful, -+ * but WITHOUT ANY WARRANTY; without even the implied warranty of -+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+ * GNU General Public License for more details. -+ * -+ * You should have received a copy of the GNU General Public License -+ * along with this software; if not, write to the Free Software -+ * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, -+ * USA. -+ */ -+ -+#ifndef __XSELECTION_H__ -+#define __XSELECTION_H__ -+ -+#include -+#include -+ -+class XSelectionHandler -+{ -+public: -+ virtual void handleXSelectionAnnounce(bool available) = 0; -+ virtual void handleXSelectionData(const char* data) = 0; -+}; -+ -+class XSelection : TXWindow -+{ -+public: -+ XSelection(Display* dpy_, XSelectionHandler* handler_); -+ -+ void handleSelectionOwnerChange(Window owner, Atom selection, Time time); -+ void requestSelectionData(); -+ void handleClientClipboardData(const char* data); -+ -+private: -+ XSelectionHandler* handler; -+ Atom probeProperty; -+ Atom transferProperty; -+ Atom timestampProperty; -+ Atom announcedSelection; -+ std::string clientData; // Always in UTF-8 -+ -+ Time getXServerTime(); -+ void announceSelection(Atom selection); -+ -+ bool selectionRequest(Window requestor, Atom selection, Atom target, -+ Atom property) override; -+ void selectionNotify(XSelectionEvent* ev, Atom type, int format, int nitems, -+ void* data) override; -+}; -+ -+#endif -diff --git a/unix/x0vncserver/x0vncserver.cxx b/unix/x0vncserver/x0vncserver.cxx -index d2999e2..b31450b 100644 ---- a/unix/x0vncserver/x0vncserver.cxx -+++ b/unix/x0vncserver/x0vncserver.cxx -@@ -281,11 +281,6 @@ int main(int argc, char** argv) - - Configuration::enableServerParams(); - -- // FIXME: We don't support clipboard yet -- Configuration::removeParam("AcceptCutText"); -- Configuration::removeParam("SendCutText"); -- Configuration::removeParam("MaxCutText"); -- - // Assume different defaults when socket activated - if (hasSystemdListeners()) - rfbport.setParam(-1); -diff --git a/unix/x0vncserver/x0vncserver.man b/unix/x0vncserver/x0vncserver.man -index 347e50e..5bc8807 100644 ---- a/unix/x0vncserver/x0vncserver.man -+++ b/unix/x0vncserver/x0vncserver.man -@@ -222,6 +222,27 @@ Accept pointer movement and button events from clients. Default is on. - Accept requests to resize the size of the desktop. Default is on. - . - .TP -+.B \-AcceptCutText -+Accept clipboard updates from clients. Default is on. -+. -+.TP -+.B \-SetPrimary -+Set the PRIMARY as well as the CLIPBOARD selection. Default is on. -+. -+.TP -+.B \-MaxCutText \fIbytes\fP -+The maximum permitted size of an incoming clipboard update. -+Default is \fB262144\fP. -+. -+.TP -+.B \-SendCutText -+Send clipboard changes to clients. Default is on. -+. -+.TP -+.B \-SendPrimary -+Send the PRIMARY as well as the CLIPBOARD selection to clients. Default is on. -+. -+.TP - .B \-RemapKeys \fImapping - Sets up a keyboard mapping. - .I mapping diff --git a/tigervnc-add-option-allowing-to-connect-only-user-owning-session.patch b/tigervnc-add-option-allowing-to-connect-only-user-owning-session.patch index 4f8a3c2..adb5a55 100644 --- a/tigervnc-add-option-allowing-to-connect-only-user-owning-session.patch +++ b/tigervnc-add-option-allowing-to-connect-only-user-owning-session.patch @@ -15,17 +15,17 @@ with 'PlainUsers=*' option allowing everyone to connect to the session. 3 files changed, 126 insertions(+), 8 deletions(-) diff --git a/common/rfb/VNCServerST.cxx b/common/rfb/VNCServerST.cxx -index 3831812..736a563 100644 +index b99d33b..aa8d53e 100644 --- a/common/rfb/VNCServerST.cxx +++ b/common/rfb/VNCServerST.cxx -@@ -696,13 +696,6 @@ void VNCServerST::queryConnection(VNCSConnectionST* client, +@@ -682,13 +682,6 @@ void VNCServerST::queryConnection(VNCSConnectionST* client, return; } - // - Are we configured to do queries? - if (!rfb::Server::queryConnect && - !client->getSock()->requiresQuery()) { -- approveConnection(client->getSock(), true, NULL); +- approveConnection(client->getSock(), true, nullptr); - return; - } - @@ -33,10 +33,10 @@ index 3831812..736a563 100644 if (client->accessCheck(AccessNoQuery)) { diff --git a/unix/xserver/hw/vnc/XserverDesktop.cc b/unix/xserver/hw/vnc/XserverDesktop.cc -index d4ee16b..fe86d36 100644 +index 260ed3a..4f252c8 100644 --- a/unix/xserver/hw/vnc/XserverDesktop.cc +++ b/unix/xserver/hw/vnc/XserverDesktop.cc -@@ -52,6 +52,11 @@ +@@ -51,6 +51,11 @@ #include "XorgGlue.h" #include "vncInput.h" @@ -48,8 +48,8 @@ index d4ee16b..fe86d36 100644 extern "C" { void vncSetGlueContext(int screenIndex); void vncPresentMscEvent(uint64_t id, uint64_t msc); -@@ -71,7 +76,15 @@ IntParameter queryConnectTimeout("QueryConnectTimeout", - "Accept Connection dialog before " +@@ -70,7 +75,15 @@ IntParameter queryConnectTimeout("QueryConnectTimeout", + "Accept connection dialog before " "rejecting the connection", 10); - @@ -65,7 +65,7 @@ index d4ee16b..fe86d36 100644 XserverDesktop::XserverDesktop(int screenIndex_, std::list listeners_, -@@ -168,11 +181,134 @@ void XserverDesktop::init(rfb::VNCServer* vs) +@@ -164,11 +177,134 @@ void XserverDesktop::init(rfb::VNCServer* vs) // ready state } @@ -201,11 +201,11 @@ index d4ee16b..fe86d36 100644 server->approveConnection(sock, false, "Another connection is currently being queried."); return; diff --git a/unix/xserver/hw/vnc/XserverDesktop.h b/unix/xserver/hw/vnc/XserverDesktop.h -index e604295..aed188e 100644 +index 8c543db..8d6bde4 100644 --- a/unix/xserver/hw/vnc/XserverDesktop.h +++ b/unix/xserver/hw/vnc/XserverDesktop.h @@ -108,6 +108,13 @@ public: - virtual void grabRegion(const rfb::Region& r); + void grabRegion(const rfb::Region& r) override; protected: +#ifdef HAVE_SYSTEMD_DAEMON @@ -219,11 +219,11 @@ index e604295..aed188e 100644 std::list* sockets, rfb::VNCServer* sockserv); diff --git a/unix/xserver/hw/vnc/Xvnc.man b/unix/xserver/hw/vnc/Xvnc.man -index b9c429f..e4822f6 100644 +index d6b1664..07b74bb 100644 --- a/unix/xserver/hw/vnc/Xvnc.man +++ b/unix/xserver/hw/vnc/Xvnc.man -@@ -204,6 +204,13 @@ to allow any user to authenticate using this security type. Specify \fB%u\fP - to allow the user of the server process. Default is to deny all users. +@@ -200,6 +200,13 @@ Never treat incoming connections as shared, regardless of the client-specified + setting. Default is off. . .TP +.B \-ApproveLoggedUserOnly diff --git a/tigervnc-add-selinux-policy-rules-allowing-access-to-proc-sys-fs-nr-open.patch b/tigervnc-add-selinux-policy-rules-allowing-access-to-proc-sys-fs-nr-open.patch new file mode 100644 index 0000000..46f9bca --- /dev/null +++ b/tigervnc-add-selinux-policy-rules-allowing-access-to-proc-sys-fs-nr-open.patch @@ -0,0 +1,27 @@ +From 313200978926cc7b7521c0d645918391b7609681 Mon Sep 17 00:00:00 2001 +From: Jan Grulich +Date: Thu, 27 Feb 2025 13:49:02 +0100 +Subject: [PATCH] Add SELinux policy rules allowing to access + /proc/sys/fs/nr_open + +This is needed when the nofile limit is set to unlimited, otherwise we +will fail to start a VNC session. +--- + unix/vncserver/selinux/vncsession.te | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/unix/vncserver/selinux/vncsession.te b/unix/vncserver/selinux/vncsession.te +index d92f1bd..2ce4fc8 100644 +--- a/unix/vncserver/selinux/vncsession.te ++++ b/unix/vncserver/selinux/vncsession.te +@@ -37,6 +37,10 @@ allow vnc_session_t self:fifo_file rw_fifo_file_perms; + allow vnc_session_t vnc_session_var_run_t:file manage_file_perms; + files_pid_filetrans(vnc_session_t, vnc_session_var_run_t, file) + ++# Allow access to /proc/sys/fs/nr_open ++# Needed when the nofile limit is set to unlimited. ++kernel_read_fs_sysctls(vnc_session_t) ++ + # Allowed to create ~/.local + optional_policy(` + gnome_filetrans_home_content(vnc_session_t) diff --git a/tigervnc-add-selinux-policy-rules-allowing-create-dirs-under-root-dir.patch b/tigervnc-add-selinux-policy-rules-allowing-create-dirs-under-root-dir.patch new file mode 100644 index 0000000..a3b4c18 --- /dev/null +++ b/tigervnc-add-selinux-policy-rules-allowing-create-dirs-under-root-dir.patch @@ -0,0 +1,47 @@ +From e652f06940f84fd8e19d7b674ae8c6000530fb40 Mon Sep 17 00:00:00 2001 +From: Jan Grulich +Date: Fri, 7 Feb 2025 15:32:49 +0100 +Subject: [PATCH] Add SELinux policy rules allowing to create directories under + /root + +We have policy that allows to create ~/.local or ~/.config, but we don't +have rule that allows the same under /root directory, where we fail in +case any of these directories doesn't exist. +--- + unix/vncserver/selinux/vncsession.te | 10 ++++++++++ + 1 file changed, 10 insertions(+) + +diff --git a/unix/vncserver/selinux/vncsession.te b/unix/vncserver/selinux/vncsession.te +index d92f1bda7d..2f49717077 100644 +--- a/unix/vncserver/selinux/vncsession.te ++++ b/unix/vncserver/selinux/vncsession.te +@@ -48,6 +48,14 @@ optional_policy(` + create_dirs_pattern(vnc_session_t, gconf_home_t, gconf_home_t) + ') + ++# Allowed to create /root/.local ++optional_policy(` ++ gen_require(` ++ type admin_home_t; ++ ') ++ create_dirs_pattern(vnc_session_t, admin_home_t, admin_home_t) ++') ++ + # Manage TigerVNC files (mainly ~/.local/state/*.log) + create_dirs_pattern(vnc_session_t, vnc_home_t, vnc_home_t) + manage_files_pattern(vnc_session_t, vnc_home_t, vnc_home_t) +@@ -88,6 +96,7 @@ optional_policy(` + gen_require(` + attribute userdomain; + type gconf_home_t; ++ type admin_home_t; + ') + userdom_admin_home_dir_filetrans(userdomain, vnc_home_t, dir, ".vnc") + userdom_user_home_dir_filetrans(userdomain, vnc_home_t, dir, ".vnc") +@@ -95,5 +104,6 @@ optional_policy(` + gnome_config_filetrans(userdomain, vnc_home_t, dir, "tigervnc") + gnome_data_filetrans(userdomain, vnc_home_t, dir, "tigervnc") + filetrans_pattern(userdomain, gconf_home_t, vnc_home_t, dir, "tigervnc") ++ filetrans_pattern(vnc_session_t, admin_home_t, vnc_home_t, dir, "tigervnc") + filetrans_pattern(vnc_session_t, gconf_home_t, vnc_home_t, dir, "tigervnc") + ') diff --git a/tigervnc-avoid-invalid-xfree-for-xclasshint.patch b/tigervnc-avoid-invalid-xfree-for-xclasshint.patch deleted file mode 100644 index bf43d09..0000000 --- a/tigervnc-avoid-invalid-xfree-for-xclasshint.patch +++ /dev/null @@ -1,24 +0,0 @@ -From 6c8387018b130eb4ef69ea377e9154ba04f0fd50 Mon Sep 17 00:00:00 2001 -From: Pierre Ossman -Date: Tue, 22 Oct 2024 09:58:27 +0200 -Subject: [PATCH] Avoid invalid XFree for XClassHint - -It seems XGetClassHint() doesn't set the pointers to NULL if there is no -name, so we need to make sure it is cleared beforehand. Otherwise we can -get an invalid pointer given to XFree(). ---- - unix/tx/TXWindow.cxx | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/unix/tx/TXWindow.cxx b/unix/tx/TXWindow.cxx -index b6a29d679..639c13827 100644 ---- a/unix/tx/TXWindow.cxx -+++ b/unix/tx/TXWindow.cxx -@@ -313,6 +313,7 @@ void TXWindow::toplevel(const char* name, TXDeleteWindowCallback* dwc_, - void TXWindow::setName(const char* name) - { - XClassHint classHint; -+ memset(&classHint, 0, sizeof(classHint)); - XGetClassHint(dpy, win(), &classHint); - XFree(classHint.res_name); - classHint.res_name = (char*)name; diff --git a/tigervnc-do-proper-toplevel-window-setup-for-selection-window.patch b/tigervnc-do-proper-toplevel-window-setup-for-selection-window.patch deleted file mode 100644 index edc285e..0000000 --- a/tigervnc-do-proper-toplevel-window-setup-for-selection-window.patch +++ /dev/null @@ -1,22 +0,0 @@ -From 9e15952d02e01b8e19e7459bcabcd47dc63a1726 Mon Sep 17 00:00:00 2001 -From: Pierre Ossman -Date: Tue, 22 Oct 2024 09:59:30 +0200 -Subject: [PATCH] Do proper top level window setup for selection window - ---- - unix/x0vncserver/XSelection.cxx | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/unix/x0vncserver/XSelection.cxx b/unix/x0vncserver/XSelection.cxx -index 72dd537f4..c724d2ac4 100644 ---- a/unix/x0vncserver/XSelection.cxx -+++ b/unix/x0vncserver/XSelection.cxx -@@ -37,7 +37,7 @@ XSelection::XSelection(Display* dpy_, XSelectionHandler* handler_) - probeProperty = XInternAtom(dpy, "TigerVNC_ProbeProperty", False); - transferProperty = XInternAtom(dpy, "TigerVNC_TransferProperty", False); - timestampProperty = XInternAtom(dpy, "TigerVNC_TimestampProperty", False); -- setName("TigerVNC Clipboard (x0vncserver)"); -+ toplevel("TigerVNC Clipboard (x0vncserver)"); - addEventMask(PropertyChangeMask); // Required for PropertyNotify events - } - diff --git a/tigervnc-dont-get-pointer-position-for-floating-device.patch b/tigervnc-dont-get-pointer-position-for-floating-device.patch deleted file mode 100644 index 3bf7dda..0000000 --- a/tigervnc-dont-get-pointer-position-for-floating-device.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/unix/xserver/hw/vnc/vncInput.c b/unix/xserver/hw/vnc/vncInput.c -index b3d0926d..d36a096f 100644 ---- a/unix/xserver/hw/vnc/vncInput.c -+++ b/unix/xserver/hw/vnc/vncInput.c -@@ -167,7 +167,7 @@ void vncPointerMove(int x, int y) - - void vncGetPointerPos(int *x, int *y) - { -- if (vncPointerDev != NULL) { -+ if (vncPointerDev != NULL && !IsFloating(vncPointerDev)) { - ScreenPtr ptrScreen; - - miPointerGetPosition(vncPointerDev, &cursorPosX, &cursorPosY); diff --git a/tigervnc-vncsession-move-existing-log-to-log-old-if-present.patch b/tigervnc-vncsession-move-existing-log-to-log-old-if-present.patch deleted file mode 100644 index 9a1ae26..0000000 --- a/tigervnc-vncsession-move-existing-log-to-log-old-if-present.patch +++ /dev/null @@ -1,94 +0,0 @@ -From e26bc65b92d1e43570619deadf20b965e0952fef Mon Sep 17 00:00:00 2001 -From: Pat Riehecky -Date: Wed, 31 Jul 2024 14:43:46 -0500 -Subject: [PATCH] vncsession: Move existing log to log.old if present - ---- - unix/vncserver/vncsession.c | 47 ++++++++++++++++++++++++++++--------- - 1 file changed, 36 insertions(+), 11 deletions(-) - -diff --git a/unix/vncserver/vncsession.c b/unix/vncserver/vncsession.c -index 98a0432aa..a10e0789e 100644 ---- a/unix/vncserver/vncsession.c -+++ b/unix/vncserver/vncsession.c -@@ -393,8 +393,9 @@ redir_stdio(const char *homedir, const char *display, char **envp) - int fd; - long hostlen; - char* hostname = NULL, *xdgstate; -- char logfile[PATH_MAX], legacy[PATH_MAX]; -+ char logdir[PATH_MAX], logfile[PATH_MAX], logfile_old[PATH_MAX], legacy[PATH_MAX]; - struct stat st; -+ size_t fmt_len; - - fd = open("/dev/null", O_RDONLY); - if (fd == -1) { -@@ -408,15 +409,24 @@ redir_stdio(const char *homedir, const char *display, char **envp) - close(fd); - - xdgstate = getenvp("XDG_STATE_HOME", envp); -- if (xdgstate != NULL && xdgstate[0] == '/') -- snprintf(logfile, sizeof(logfile), "%s/tigervnc", xdgstate); -- else -- snprintf(logfile, sizeof(logfile), "%s/.local/state/tigervnc", homedir); -+ if (xdgstate != NULL && xdgstate[0] == '/') { -+ fmt_len = snprintf(logdir, sizeof(logdir), "%s/tigervnc", xdgstate); -+ if (fmt_len >= sizeof(logdir)) { -+ syslog(LOG_CRIT, "Log dir path too long"); -+ _exit(EX_OSERR); -+ } -+ } else { -+ fmt_len = snprintf(logdir, sizeof(logdir), "%s/.local/state/tigervnc", homedir); -+ if (fmt_len >= sizeof(logdir)) { -+ syslog(LOG_CRIT, "Log dir path too long"); -+ _exit(EX_OSERR); -+ } -+ } - - snprintf(legacy, sizeof(legacy), "%s/.vnc", homedir); -- if (stat(logfile, &st) != 0 && stat(legacy, &st) == 0) { -+ if (stat(logdir, &st) != 0 && stat(legacy, &st) == 0) { - syslog(LOG_WARNING, "~/.vnc is deprecated, please consult 'man vncsession' for paths to migrate to."); -- strcpy(logfile, legacy); -+ strcpy(logdir, legacy); - - #ifdef HAVE_SELINUX - /* this is only needed to handle historical type changes for the legacy dir */ -@@ -431,9 +441,9 @@ redir_stdio(const char *homedir, const char *display, char **envp) - #endif - } - -- if (mkdir_p(logfile, 0755) == -1) { -+ if (mkdir_p(logdir, 0755) == -1) { - if (errno != EEXIST) { -- syslog(LOG_CRIT, "Failure creating \"%s\": %s", logfile, strerror(errno)); -+ syslog(LOG_CRIT, "Failure creating \"%s\": %s", logdir, strerror(errno)); - _exit(EX_OSERR); - } - } -@@ -450,9 +460,24 @@ redir_stdio(const char *homedir, const char *display, char **envp) - _exit(EX_OSERR); - } - -- snprintf(logfile + strlen(logfile), sizeof(logfile) - strlen(logfile), "/%s%s.log", -- hostname, display); -+ fmt_len = snprintf(logfile, sizeof(logfile), "/%s/%s%s.log", logdir, hostname, display); -+ if (fmt_len >= sizeof(logfile)) { -+ syslog(LOG_CRIT, "Log path too long"); -+ _exit(EX_OSERR); -+ } -+ fmt_len = snprintf(logfile_old, sizeof(logfile_old), "/%s/%s%s.log.old", logdir, hostname, display); -+ if (fmt_len >= sizeof(logfile)) { -+ syslog(LOG_CRIT, "Log.old path too long"); -+ _exit(EX_OSERR); -+ } - free(hostname); -+ -+ if (stat(logfile, &st) == 0) { -+ if (rename(logfile, logfile_old) != 0) { -+ syslog(LOG_CRIT, "Failure renaming log file \"%s\" to \"%s\": %s", logfile, logfile_old, strerror(errno)); -+ _exit(EX_OSERR); -+ } -+ } - fd = open(logfile, O_CREAT | O_WRONLY | O_TRUNC, 0644); - if (fd == -1) { - syslog(LOG_CRIT, "Failure creating log file \"%s\": %s", logfile, strerror(errno)); diff --git a/tigervnc.spec b/tigervnc.spec index c06dfbe..cae2928 100644 --- a/tigervnc.spec +++ b/tigervnc.spec @@ -4,8 +4,8 @@ %global modulename vncsession Name: tigervnc -Version: 1.14.1 -Release: 4%{?dist} +Version: 1.15.0 +Release: 1%{?dist} Summary: A TigerVNC remote display system %global _hardened_build 1 @@ -13,7 +13,7 @@ Summary: A TigerVNC remote display system License: GPL-2.0-or-later URL: http://www.tigervnc.com -Source0: %{name}-%{version}.tar.gz +Source0: https://github.com/TigerVNC/%{name}/archive/v%{version}.tar.gz#/%{name}-%{version}.tar.gz Source1: xvnc.service Source2: xvnc.socket Source3: 10-libvnc.conf @@ -29,18 +29,13 @@ Patch2: tigervnc-vncsession-restore-script-systemd-service.patch Patch3: tigervnc-add-option-allowing-to-connect-only-user-owning-session.patch # Upstream patches -Patch50: tigervnc-vncsession-move-existing-log-to-log-old-if-present.patch -Patch51: tigervnc-add-clipboard-support-to-x0vncserver.patch -Patch52: tigervnc-do-proper-toplevel-window-setup-for-selection-window.patch -Patch53: tigervnc-avoid-invalid-xfree-for-xclasshint.patch +Patch50: tigervnc-add-selinux-policy-rules-allowing-create-dirs-under-root-dir.patch +Patch51: tigervnc-add-selinux-policy-rules-allowing-access-to-proc-sys-fs-nr-open.patch # Upstreamable patches -Patch80: tigervnc-dont-get-pointer-position-for-floating-device.patch -# This is tigervnc-%%{version}/unix/xserver116.patch rebased on the latest xorg -Patch100: tigervnc-xserver120.patch # 1326867 - [RHEL7.3] GLX applications in an Xvnc session fails to start -Patch101: 0001-rpath-hack.patch +Patch100: 0001-rpath-hack.patch # XServer patches @@ -107,6 +102,7 @@ Requires(postun):coreutils Requires: hicolor-icon-theme Requires: tigervnc-license Requires: tigervnc-icons +Requires: which %description Virtual Network Computing (VNC) is a remote display system which @@ -142,8 +138,11 @@ Requires(preun): systemd Requires(postun): systemd Requires(post): systemd -Requires: mesa-dri-drivers, xkeyboard-config, xkbcomp -Requires: tigervnc-license, dbus-x11 +Requires: dbus-x11 +Requires: mesa-dri-drivers +Requires: tigervnc-license +Requires: xkbcomp +Requires: xkeyboard-config %description server-minimal The VNC system allows you to access the same desktop from a wide @@ -199,9 +198,8 @@ pushd unix/xserver for all in `find . -type f -perm -001`; do chmod -x "$all" done -# Xorg patches -%patch -P100 -p1 -b .xserver120-rebased -%patch -P101 -p1 -b .rpath +%patch -P100 -p1 -b .rpath +cat ../xserver120.patch | patch -p1 popd # Tigervnc patches @@ -210,13 +208,10 @@ popd %patch -P3 -p1 -b .add-option-allowing-to-connect-only-user-owning-session # Upstream patches -%patch -P50 -p1 -b .vncsession-move-existing-log-to-log-old-if-present -%patch -P51 -p1 -b .add-clipboard-support-to-x0vncserver -%patch -P52 -p1 -b .do-proper-toplevel-window-setup-for-selection-window -%patch -P53 -p1 -b .avoid-invalid-xfree-for-xclasshint +%patch -P50 -p1 -b .add-selinux-policy-rules-allowing-create-dirs-under-root-dir +%patch -P51 -p1 -b .add-selinux-policy-rules-allowing-access-to-proc-sys-fs-nr-open # Upstreamable patches -%patch -P80 -p1 -b .dont-get-pointer-position-for-floating-device %build %ifarch sparcv9 sparc64 s390 s390x @@ -237,7 +232,7 @@ mkdir -p %{%__cmake_builddir} pushd unix/xserver %if 0%{?fedora} > 32 || 0%{?rhel} >= 9 -sed -i 's@TIGERVNC_BUILDDIR=${TIGERVNC_SRCDIR}@TIGERVNC_BUILDDIR=${TIGERVNC_SRCDIR}/%{_target_platform}@g' hw/vnc/Makefile.am +sed -i 's@TIGERVNC_BUILDDIR=${top_builddir}/\.\./\.\.@TIGERVNC_BUILDDIR=${TIGERVNC_SRCDIR}/%{_target_platform}@g' hw/vnc/Makefile.am %endif autoreconf -fiv @@ -245,10 +240,8 @@ autoreconf -fiv --disable-xorg --disable-xnest --disable-xvfb --disable-dmx \ --disable-xwin --disable-xephyr --disable-kdrive --disable-xwayland \ --with-pic --disable-static \ - --with-default-font-path="catalogue:%{_sysconfdir}/X11/fontpath.d,built-ins" \ - --with-fontdir=%{_datadir}/X11/fonts \ + --with-default-font-path="catalogue:/etc/X11/fontpath.d,built-ins" \ --with-xkb-output=%{_localstatedir}/lib/xkb \ - --enable-install-libxf86config \ --enable-glx --disable-dri --enable-dri2 --enable-dri3 \ --disable-unit-tests \ --disable-config-hal \ @@ -400,6 +393,30 @@ fi %ghost %verify(not md5 size mode mtime) %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} %changelog +* Fri Mar 07 2025 Jan Grulich - 1.15.0-1 +- 1.15.0 + Resolves: RHEL-78617 +- Add SELinux policy rules allowing to access /proc/sys/fs/nr_open + Resolves: RHEL-77973 +- Add SELinux policy rules allowing to create directories under /root + Resolves: RHEL-77975 +- Fix CVE-2025-26594 xorg-x11-server Use-after-free of the root cursor + Resolves: RHEL-80208 +- Fix CVE-2025-26595 xorg-x11-server Buffer overflow in XkbVModMaskText() + Resolves: RHEL-80189 +- Fix CVE-2025-26596 xorg-x11-server Heap overflow in XkbWriteKeySyms() + Resolves: RHEL-80194 +- Fix CVE-2025-26597 xorg-x11-server Buffer overflow in XkbChangeTypesOfKey() + Resolves: RHEL-80196 +- Fix CVE-2025-26598 xorg-x11-server Out-of-bounds write in CreatePointerBarrierClient() + Resolves: RHEL-80197 +- Fix CVE-2025-26599 xorg-x11-server Use of uninitialized pointer in compRedirectWindow() + Resolves: RHEL-80206 +- Fix CVE-2025-26600 xorg-x11-server Use-after-free in PlayReleasedEvents() + Resolves: RHEL-80205 +- Fix CVE-2025-26601 xorg-x11-server Use-after-free in SyncInitTrigger() + Resolves: RHEL-80209 + * Tue Jan 21 2025 Jan Grulich - 1.14.1-4 - Fix crash in clipboard support in x0vncserver Resolves: RHEL-74216