Bug 31070 - x11-server, x11-server-xwayland new security issues CVE-2022-355[01]
Summary: x11-server, x11-server-xwayland new security issues CVE-2022-355[01]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-11-02 22:07 CET by David Walser
Modified: 2022-12-15 04:11 CET (History)
6 users (show)

See Also:
Source RPM: x11-server-21.1.4-1.mga9.src.rpm, x11-server-xwayland-22.1.3-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-11-02 22:07:18 CET
SUSE has issued an advisory today (November 2):
https://lists.suse.com/pipermail/sle-security-updates/2022-November/012799.html

The issues are fixed upstream in xwayland 22.1.4 (22.1.5 has since been released):
https://lists.x.org/archives/xorg-announce/2022-October/003237.html

No new xorg-server release has been tagged yet with the fixes.
David Walser 2022-11-02 22:07:29 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patches available from upstream

Comment 2 Lewis Smith 2022-11-03 20:22:08 CET
These SRPMS are nominally with tv, so assigning this bug to you.
Noticing that tmb has done most of recent updates to both, CC'ing you.

Assignee: bugsquad => thierry.vignaud
CC: (none) => tmb

Comment 3 David Walser 2022-11-10 23:42:37 CET
openSUSE has issued an advisory for xwayland today (November 10):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3FYL6LL3R5FHAPM6C4AYXJAYVE6XH36D/
Comment 4 David Walser 2022-11-11 18:22:06 CET
Debian-LTS has issued an advisory for x11-server on November 10:
https://www.debian.org/lts/security/2022/dla-3185
Comment 5 Thomas Backlund 2022-11-11 21:30:36 CET
Cauldron already have xwayland 22.1.5

Cauldrn x11-server fixed in  x11-server-21.1.4-2.mga9 just submitted.

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8

Comment 6 Thomas Backlund 2022-11-12 00:39:10 CET
SRPM:
x11-server-1.20.14-4.mga8.src.rpm


i586:
x11-server-1.20.14-4.mga8.i586.rpm
x11-server-common-1.20.14-4.mga8.i586.rpm
x11-server-devel-1.20.14-4.mga8.i586.rpm
x11-server-source-1.20.14-4.mga8.noarch.rpm
x11-server-xdmx-1.20.14-4.mga8.i586.rpm
x11-server-xephyr-1.20.14-4.mga8.i586.rpm
x11-server-xnest-1.20.14-4.mga8.i586.rpm
x11-server-xorg-1.20.14-4.mga8.i586.rpm
x11-server-xvfb-1.20.14-4.mga8.i586.rpm
x11-server-xwayland-1.20.14-4.mga8.i586.rpm


x86_64:
x11-server-1.20.14-4.mga8.x86_64.rpm
x11-server-common-1.20.14-4.mga8.x86_64.rpm
x11-server-devel-1.20.14-4.mga8.x86_64.rpm
x11-server-source-1.20.14-4.mga8.noarch.rpm
x11-server-xdmx-1.20.14-4.mga8.x86_64.rpm
x11-server-xephyr-1.20.14-4.mga8.x86_64.rpm
x11-server-xnest-1.20.14-4.mga8.x86_64.rpm
x11-server-xorg-1.20.14-4.mga8.x86_64.rpm
x11-server-xvfb-1.20.14-4.mga8.x86_64.rpm
x11-server-xwayland-1.20.14-4.mga8.x86_64.rpm

Assignee: thierry.vignaud => qa-bugs

Comment 7 Brian Rockwell 2022-11-14 17:38:07 CET
MGA8-64, Xfce, Celeron

This is a laptop I actively use, so restricting installs to objects already present.

The following 3 packages are going to be installed:

- x11-server-common-1.20.14-4.mga8.x86_64
- x11-server-xorg-1.20.14-4.mga8.x86_64
- x11-server-xwayland-1.20.14-4.mga8.x86_64

64B of additional disk space will be used.

-- rebooted


Working as expected.

CC: (none) => brtians1

Comment 8 Thomas Andrews 2022-11-15 15:29:29 CET
MGA8-64 Plasma, i5-2500, Intel graphics.

No installation issues. This system has been run for roughly 24 hours since updating, doing normal tasks, shut down in the evening and rebooted the next day, all with no ill effects noted.

CC: (none) => andrewsfarm

Comment 9 Morgan Leijström 2022-11-15 19:39:49 CET
mga8-64, Plasma, nvidia-current, backport kernel
My usual workstation "svarten"

- x11-server-common-1.20.14-4.mga8.x86_64
- x11-server-xephyr-1.20.14-4.mga8.x86_64
- x11-server-xnest-1.20.14-4.mga8.x86_64
- x11-server-xorg-1.20.14-4.mga8.x86_64
- x11-server-xwayland-1.20.14-4.mga8.x86_64

Reboot
works, incl VirtuaBox MSW7 guest.

CC: (none) => fri

Comment 10 Dave Hodgins 2022-11-18 22:16:56 CET
No regressions noticed. Advisory committed to svn. Validating the update.

CC: (none) => davidwhodgins, sysadmin-bugs
Keywords: (none) => advisory, validated_update
Whiteboard: (none) => MGA8-64-OK

Comment 11 Mageia Robot 2022-11-18 23:52:04 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0431.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

David Walser 2022-12-15 04:11:04 CET

Status comment: Patches available from upstream => (none)


Note You need to log in before you can comment on or make changes to this bug.