[DSA 5872-1] xorg-server security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5872-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
February 28, 2025                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : xorg-server
CVE ID         : CVE-2025-26594 CVE-2025-26595 CVE-2025-26596 CVE-2025-26597
                 CVE-2025-26598 CVE-2025-26599 CVE-2025-26600 CVE-2025-26601
Debian Bug     : 1098906

Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server,
which may result in privilege escalation if the X server is running
privileged.

For the stable distribution (bookworm), these problems have been fixed in
version 2:21.1.7-3+deb12u9.

We recommend that you upgrade your xorg-server packages.

For the detailed security status of xorg-server please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/xorg-server

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmfCFt5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0SS8Q//eLaDwTOIeWM1/qLsuUBr5j5EtiLOBQI9Q+yxa3wobdKSNkbcgndsnhb4
8H0/wFjDRTs95eNegPjnaVD1Beu9nHEldMAGlFt8baHOFG9h6ngjG6mQaK5dj3s1
MdmsOCJ0yva49q3A9LLpF9r8ZCbzZvSHEXzqOkqKNEoQ+crx4zgyplDdmEyuwfFS
D4NU5IY4ncFac3bnYApbA2bGrfloM5DbRWXwr1jfa2Q6NQ4ZdOMdaexH/3bPJ7n6
dCDuyaxBZ577iUeMnOHRYdZB4PLyVpjxjs/sITlTqKTUMSxMvhDYG1d6QGJXEhRi
5bvRSbviucF0F2NCts3Z8Q6oG0M7GzoGEdwsAP/LWcTalmf+3Xo7ZzAmnV5qWtF5
G0BpmQ52G5znA9Ph9iHDROQLFmmOD2Ol7m+blL0ClCdtQ1tLf6BHG9MfM7iUMqqq
jliwXKCBLJb+72uG2r49LzOLlemttrOKCG8ope8JPD6lnZ60uTKLgbLLrq10YFbT
u7U/FV6onS90DV9Xoi2oimoGRJ5iS4rhoaz0xlM81gzTzQIWJs9K/Ljw5nxX1FmF
s/8Bntrzs+7vc5yVL5X8ZEMkLrsmw51gErrpK9FQ/OVxxXMzkLF/8lsUSe7qu9Ac
FsBQte4Q01Fy2ckJoIx2S2hsJYnlaQNrFY1iIewW6aWX6lGoEbY=
=54wR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.