Commit Graph

32 Commits

Author SHA1 Message Date
Jan Grulich
0fe3a2b6b3 Fix CVE-2025-62229: xorg-x11-server: Use-after-free in XPresentNotify structures creation
Resolves: RHEL-119979

Fix CVE-2025-62230: xorg-x11-server: Use-after-free in Xkb client resource removal
Resolves: RHEL-120001

Fix CVE-2025-62231: xorg-x11-server: Value overflow in Xkb extension XkbSetCompatMap()
Resolves: RHEL-120762
2025-10-31 15:30:13 +01:00
Jan Grulich
8996d74184 Additional fix to CVE-2025-49176: xorg-x11-server: Integer Overflow in Big Requests Extension
Resolves: RHEL-97294
2025-06-18 16:00:48 +02:00
Jan Grulich
eb8a57c918 Fix CVE-2025-49175: xorg-x11-server: Out-of-Bounds Read in X Rendering Extension Animated Cursors
Resolves: RHEL-97268

Fix CVE-2025-49176: xorg-x11-server: Integer Overflow in Big Requests Extension
Resolves: RHEL-97294

Fix CVE-2025-49178: xorg-x11-server: Unprocessed Client Request Due to Bytes to Ignore
Resolves: RHEL-97364

Fix CVE-2025-49179: xorg-x11-server: Integer overflow in X Record extension
Resolves: RHEL-97397

Fix CVE-2025-49180: xorg-x11-server: Integer Overflow in X Resize, Rotate and Reflect (RandR) Extension
Resolves: RHEL-97232
2025-06-17 17:42:17 +02:00
Jan Grulich
27d686ac04 Fix broken authentication with x0vncserver
Resolves: RHEL-93729
2025-05-27 14:47:38 +02:00
Jan Grulich
e0ab3bd641 Add option "ApproveLoggedUserOnly" allowing to connect only the user
owning the running session

Resolves: RHEL-91104
2025-05-15 09:24:31 +02:00
Jan Grulich
a362a30835 Only warn about 8 characters limit, but let it proceed
Resolves: RHEL-89430
2025-05-02 13:56:22 +02:00
Jan Grulich
3d8d7d64dc Fix inetd mode not working
Resolves: RHEL-86513
2025-04-16 08:24:24 +02:00
Jan Grulich
eea301f0d9 1.15.0
Resolves: RHEL-79161
Resolves: RHEL-79982
2025-03-03 13:18:15 +01:00
Jan Grulich
8f24055506 Fix CVE-2025-26594 xorg-x11-server Use-after-free of the root cursor
Resolves: RHEL-79397

Fix CVE-2025-26595 xorg-x11-server Buffer overflow in XkbVModMaskText()
Resolves: RHEL-79401

Fix CVE-2025-26596 xorg-x11-server Heap overflow in XkbWriteKeySyms()
Resolves: RHEL-79386

Fix CVE-2025-26597 xorg-x11-server Buffer overflow in XkbChangeTypesOfKey()
Resolves: RHEL-79380

Fix CVE-2025-26598 xorg-x11-server Out-of-bounds write in CreatePointerBarrierClient()
Resolves: RHEL-79369

Fix CVE-2025-26599 xorg-x11-server Use of uninitialized pointer in compRedirectWindow()
Resolves: RHEL-79364

Fix CVE-2025-26600 xorg-x11-server Use-after-free in PlayReleasedEvents()
Resolves: RHEL-79360

Fix CVE-2025-26601 xorg-x11-server Use-after-free in SyncInitTrigger()
Resolves: RHEL-79348
2025-02-26 08:47:10 +01:00
Jan Grulich
4bc9e172a8 Fix CVE-2024-9632: xorg-x11-server: heap-based buffer overflow privilege escalation vulnerability
Resolves: RHEL-61999
2024-10-31 13:08:36 +01:00
Jan Grulich
81e5dc3954 vncsession: use /bin/sh if the user shell is not set
Resolves: RHEL-52827
2024-08-05 13:46:28 +02:00
Jan Grulich
2ae9746371 Fix FTBS: drop already applied Xorg patches
Resolves: RHEL-46696
2024-07-12 13:26:08 +02:00
Jan Grulich
f73ec18752 vncconfig: add option to force view-only remote client connections
Resolves: RHEL-11908
2024-05-28 13:08:35 +02:00
Jan Grulich
a6399b88df Drop patches that are already part of xorg-x11-server
Resolves: RHEL-30755
Resolves: RHEL-30767
Resolves: RHEL-30761
2024-04-16 10:03:32 +02:00
Jan Grulich
ea7d05a241 Fix CVE-2024-31080 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
Resolves: RHEL-30755

Fix CVE-2024-31083 tigervnc: xorg-x11-server: User-after-free in ProcRenderAddGlyphs
Resolves: RHEL-30767

Fix CVE-2024-31081 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
Resolves: RHEL-30761
2024-04-12 09:05:00 +02:00
Jan Grulich
620a2751af Fix use after free related to CVE-2024-21886
Resolves: RHEL-20388

Fix copy/paste error in the DeviceStateNotify
Resolves: RHEL-20530
2024-02-07 13:33:00 +01:00
Jan Grulich
17a271c1e7 Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
Resolves: RHEL-20388

Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
Resolves: RHEL-20382

Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
Resolves: RHEL-20530

Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
Resolves: RHEL-21214
2024-01-22 10:00:29 +01:00
Jan Grulich
c32f5f2f67 Use dup() to get available file descriptor when using -inetd option
Resolves: RHEL-21000
2024-01-08 15:10:42 +01:00
Jan Grulich
da041a367f Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
Resolves: RHEL-18410

Fix CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
Resolves: RHEL-18422
2024-01-02 13:56:21 +01:00
Jan Grulich
7724b17e75 Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
Resolves: RHEL-15236

Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
Resolves: RHEL-15230
2023-11-02 09:36:01 +01:00
Jan Grulich
38aa048031 Support username alias in PlainUsers
Resolves: RHEL-4258
2023-10-09 12:22:56 +02:00
Jan Grulich
13cc84c5f4 xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability
Resolves: bz#2180306
2023-04-11 14:14:15 +02:00
Jan Grulich
336a88a061 1.13.1
Resolves: bz#2175748

Restore "--fallbacktofreeport" option in the vncserver script
Resolves: bz#2174398
2023-03-21 13:20:03 +01:00
Troy Dawson
0d6ad6a457 Bring rpminspect.yaml over from Brew dist-git
Signed-off-by: Troy Dawson <tdawson@redhat.com>
2023-03-10 11:59:49 -08:00
Troy Dawson
1d0e23e36f Bring gating.yaml over from Brew dist-git
Signed-off-by: Troy Dawson <tdawson@redhat.com>
2023-03-10 11:59:49 -08:00
CentOS Sources
b04f300865 Auto sync2gitlab import of tigervnc-1.12.0-9.el8.src.rpm 2022-12-13 06:27:12 +00:00
CentOS Sources
848aa2a2c4 Auto sync2gitlab import of tigervnc-1.12.0-8.el8.src.rpm 2022-12-06 08:12:50 +00:00
CentOS Sources
fb465e9af4 Auto sync2gitlab import of tigervnc-1.12.0-7.el8.src.rpm 2022-08-27 12:18:37 +00:00
CentOS Sources
b918f56ff8 Auto sync2gitlab import of tigervnc-1.12.0-6.el8.src.rpm 2022-08-19 18:19:55 +00:00
CentOS Sources
7671a256c5 Auto sync2gitlab import of tigervnc-1.12.0-5.el8.src.rpm 2022-06-02 14:32:20 +00:00
James Antill
0553279b85 Auto sync2gitlab import of tigervnc-1.12.0-4.el8.src.rpm 2022-05-26 15:38:05 -04:00
James Antill
4facd733d1 Initial c8s branch. 2022-05-26 15:38:02 -04:00