[DSA 5947-1] xorg-server security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5947-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
June 23, 2025                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : xorg-server
CVE ID         : CVE-2025-49175 CVE-2025-49176 CVE-2025-49177 CVE-2025-49178
                 CVE-2025-49179 CVE-2025-49180

Nils Emmerich discovered several vulnerabilities in the Xorg X server,
which may result in privilege escalation if the X server is running
privileged.

For the stable distribution (bookworm), these problems have been fixed in
version 2:21.1.7-3+deb12u10.

We recommend that you upgrade your xorg-server packages.

For the detailed security status of xorg-server please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/xorg-server

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmhZn11fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0T/Sw/8C2nHgLAm7Sf0/xxYtix6j8YytXJy/2RT0EMFFLNjSVPtOloqb4BC4xoc
3W0XRd7X1DvLEMTYCDDroLLbWBTT5GUdGtVYRXUgjrGhP840YoDj6pAmHa11HmAM
tVzN9EfbYEBINlUZ4yyIpXxnhXdo7oZUa32+dOmWjxT6dDgMrbo8xLsyd8B/z6Z7
jcK6qKBhQxWhNvT2tsvXVb2pLDPRLJxZ0ACnk720mc19a9O2yOBqwRx0Ycipy70X
g8vHLkblb0cd4LLBZGwv7BHoMlQlFM2AbqhrfYKqPYsVoG7tw3n2Ow3Ahl3tLFjC
l63NDyvVUR44xMjtWG132s8afO3m3vlS56aagPFmA5st+/Y/9fl2nuy8iumEPrxc
corjjSnyhwQmwQ78PDPOoCSWu+QjmC1Zx9YGPpuUHF/+O1ISLGqfZUnS+gqcvZxG
VFL2f05c/yhejaweQM6ua5kHkKOLnaekpajd3LAcuZlH7KJjnMvEDJmogaEB3QCY
incyTeMUjHhBgWBwYzDOH9S3V0fQOZxWygh7hYk1YMXfApiJ9Tz4cIcEDLzijbBw
XlcXYDiumTdd2fnSpzFbTI56jbyCW8SfAoqq+4aRg/8PFwjssLYEmPJXw8EMeKHn
/XowNcP/6kbftgyANuMwDmfaNcIrn5n9m2IZc+ymF/6fwuj4Jpg=
=CU4R
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.