{"id":2223188,"url":"http://patchwork.ozlabs.org/api/1.1/patches/2223188/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/patch/20260414163424.2355464-2-bernd@kuhls.net/","project":{"id":27,"url":"http://patchwork.ozlabs.org/api/1.1/projects/27/?format=json","name":"Buildroot development","link_name":"buildroot","list_id":"buildroot.buildroot.org","list_email":"buildroot@buildroot.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260414163424.2355464-2-bernd@kuhls.net>","date":"2026-04-14T16:34:24","name":"[2/2] package/x11r7/xwayland: security bump version to 24.1.10","commit_ref":null,"pull_url":null,"state":"accepted","archived":false,"hash":"3956db94d75b73631d6b9b37735124544a78f39c","submitter":{"id":86624,"url":"http://patchwork.ozlabs.org/api/1.1/people/86624/?format=json","name":"Bernd Kuhls","email":"bernd@kuhls.net"},"delegate":{"id":89618,"url":"http://patchwork.ozlabs.org/api/1.1/users/89618/?format=json","username":"juju","first_name":"Julien","last_name":"Olivain","email":"juju@cotds.org"},"mbox":"http://patchwork.ozlabs.org/project/buildroot/patch/20260414163424.2355464-2-bernd@kuhls.net/mbox/","series":[{"id":499870,"url":"http://patchwork.ozlabs.org/api/1.1/series/499870/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/list/?series=499870","date":"2026-04-14T16:34:23","name":"[1/2] package/x11r7/xserver_xorg-server: security bump version to 21.1.22","version":1,"mbox":"http://patchwork.ozlabs.org/series/499870/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2223188/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2223188/checks/","tags":{},"headers":{"Return-Path":"<buildroot-bounces@buildroot.org>","X-Original-To":["incoming-buildroot@patchwork.ozlabs.org","buildroot@buildroot.org"],"Delivered-To":["patchwork-incoming-buildroot@legolas.ozlabs.org","buildroot@buildroot.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=jOyMbjx0;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=2605:bc80:3010::136; helo=smtp3.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)"],"Received":["from smtp3.osuosl.org (smtp3.osuosl.org [IPv6:2605:bc80:3010::136])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fw8xv4Kr8z1yCv\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Wed, 15 Apr 2026 02:34:43 +1000 (AEST)","from localhost (localhost [127.0.0.1])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id C3DDA6F4A1;\n\tTue, 14 Apr 2026 16:34:41 +0000 (UTC)","from smtp3.osuosl.org ([127.0.0.1])\n by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id CzwvWuefJm8X; Tue, 14 Apr 2026 16:34:41 +0000 (UTC)","from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id EF2BF6F49E;\n\tTue, 14 Apr 2026 16:34:40 +0000 (UTC)","from smtp2.osuosl.org (smtp2.osuosl.org [IPv6:2605:bc80:3010::133])\n by lists1.osuosl.org (Postfix) with ESMTP id 9C835375\n for <buildroot@buildroot.org>; Tue, 14 Apr 2026 16:34:39 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n by smtp2.osuosl.org (Postfix) with ESMTP id 8E48B403F0\n for <buildroot@buildroot.org>; Tue, 14 Apr 2026 16:34:39 +0000 (UTC)","from smtp2.osuosl.org ([127.0.0.1])\n by localhost (smtp2.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id J3QohYeeevIz for <buildroot@buildroot.org>;\n Tue, 14 Apr 2026 16:34:38 +0000 (UTC)","from dd20012.kasserver.com (dd20012.kasserver.com [85.13.140.57])\n by smtp2.osuosl.org (Postfix) with ESMTPS id 1232E4012B\n for <buildroot@buildroot.org>; Tue, 14 Apr 2026 16:34:37 +0000 (UTC)","from fli4l.lan.fli4l (p54a1be9a.dip0.t-ipconnect.de\n [84.161.190.154])\n by dd20012.kasserver.com (Postfix) with ESMTPSA id 86835A4C234F;\n Tue, 14 Apr 2026 18:34:24 +0200 (CEST)","from bruckner.lan.fli4l ([192.168.1.1]:53522)\n by fli4l.lan.fli4l with esmtp (Exim 4.99.1)\n (envelope-from <bernd@kuhls.net>) id 1wCgiV-000000008Pi-3lK2;\n Tue, 14 Apr 2026 16:34:24 +0000"],"X-Virus-Scanned":["amavis at osuosl.org","amavis at osuosl.org"],"X-Comment":"SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ","DKIM-Filter":["OpenDKIM Filter v2.11.0 smtp3.osuosl.org EF2BF6F49E","OpenDKIM Filter v2.11.0 smtp2.osuosl.org 1232E4012B"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1776184481;\n\tbh=B57lOVmNZGhJKp6WHkymFoM2OJd6iidiFOUN6GZqXo8=;\n\th=From:To:Cc:Date:In-Reply-To:References:Subject:List-Id:\n\t List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe:\n\t From;\n\tb=jOyMbjx0LUwrHTRQXscu5JWixtvDDZcOlpuS25ykeM/CR/0Fc3swqqGvIIaYd22dC\n\t qI4YmP+QK30hhcPPB2Nw/bcQb6MIOq2P+/ywI/9uNNIw9PxG15BmYdRWBM7hdYKyMy\n\t AbDxe1rv5nlfF5qdMa9BjCSb1Eym2AyKetRcTWitKn37EoU7kcvDNlCJ5+V98RNDX2\n\t c7YGh+U2lPhQdvbEE08G1f/hXkwBBNFiGvnRdety3en6uGNKaz0vaTu2Hia7nhqJZi\n\t QvbV4Dgo7kw2/htnOBkE9+NUavQLsShpOkNfceeJ7vNj9IrVu0Pcqh6UuXizujtI+t\n\t MlpLjJ28okFEw==","Received-SPF":"Pass (mailfrom) identity=mailfrom; client-ip=85.13.140.57;\n helo=dd20012.kasserver.com; envelope-from=bernd@kuhls.net;\n receiver=<UNKNOWN>","DMARC-Filter":"OpenDMARC Filter v1.4.2 smtp2.osuosl.org 1232E4012B","From":"Bernd Kuhls <bernd@kuhls.net>","To":"buildroot@buildroot.org","Cc":"Raphael Pavlidis <raphael.pavlidis@gmail.com>","Date":"Tue, 14 Apr 2026 18:34:24 +0200","Message-ID":"<20260414163424.2355464-2-bernd@kuhls.net>","X-Mailer":"git-send-email 2.47.3","In-Reply-To":"<20260414163424.2355464-1-bernd@kuhls.net>","References":"<20260414163424.2355464-1-bernd@kuhls.net>","MIME-Version":"1.0","X-Spamd-Bar":"--","X-Mailman-Original-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=kuhls.net;\n s=kas202511301023; t=1776184464;\n bh=UpurXloHz7XaWRiG8yhcnUmfvEV2ijCwLnHIs/11EfM=;\n h=From:To:Cc:Subject:Date:In-Reply-To:From;\n b=qU0oKzoEDrN0eI6YE//ecLP9SPyZweQuEVJF5IPyAm+A0xWbvDEwaFbUv0SCFLAsI\n pAX+/B5Q6dnuPU/I5AGvIk6y4mWjKnw2+gU3MfFf4e0mGemHw7iHYNsX6ab2uyJYJO\n /mG++APlR8ph7pV4toPNWqrOgz8VFWVr7/YpCRGC35L0qsReL0pPZSXHKwlvW37W1/\n 9MWK8jRkjY3n3v1UGHFIpHLLDaKeV+oKy/Ko4jUEgGc64tYuHk/U5tTMQ7P/dYZMYm\n pxYrH1/3+LNfVdcSRTfxrxRWNhvYj2CdDsUaliQp5FPd6fB7d9ZyYzLq24nMwwe3fK\n w531yIHQoCrMA==","X-Mailman-Original-Authentication-Results":["smtp2.osuosl.org;\n dmarc=pass (p=none dis=none)\n header.from=kuhls.net","smtp2.osuosl.org;\n dkim=pass (2048-bit key) header.d=kuhls.net header.i=@kuhls.net\n header.a=rsa-sha256 header.s=kas202511301023 header.b=qU0oKzoE"],"Subject":"[Buildroot] [PATCH 2/2] package/x11r7/xwayland: security bump\n version to 24.1.10","X-BeenThere":"buildroot@buildroot.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.buildroot.org>","List-Unsubscribe":"<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>","List-Archive":"<http://lists.buildroot.org/pipermail/buildroot/>","List-Post":"<mailto:buildroot@buildroot.org>","List-Help":"<mailto:buildroot-request@buildroot.org?subject=help>","List-Subscribe":"<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"buildroot-bounces@buildroot.org","Sender":"\"buildroot\" <buildroot-bounces@buildroot.org>"},"content":"https://lists.x.org/archives/xorg-announce/2026-April/003679.html\n\nUpdated license hash due to upstream commits:\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/e5c6a5ab905e0158ec22877b4117f10bef6e4140\nhttps://gitlab.freedesktop.org/xorg/xserver/-/commit/89f82cce4a4ca480501c130231968a72cafa952d\n\nFixes the following CVEs:\n\n* CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap()\n* CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom()\n* CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence()\n* CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap()\n* CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes()\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n---\n package/x11r7/xwayland/xwayland.hash | 8 ++++----\n package/x11r7/xwayland/xwayland.mk   | 2 +-\n 2 files changed, 5 insertions(+), 5 deletions(-)","diff":"diff --git a/package/x11r7/xwayland/xwayland.hash b/package/x11r7/xwayland/xwayland.hash\nindex 0d1df29b43..ba84d20b9f 100644\n--- a/package/x11r7/xwayland/xwayland.hash\n+++ b/package/x11r7/xwayland/xwayland.hash\n@@ -1,6 +1,6 @@\n-# From https://lists.x.org/archives/xorg/2025-October/062148.html\n-sha256  f297af27a84508db9b80d1cbbcc69c3801da38eb64c72f3b5b50f582459afdd0  xwayland-24.1.9.tar.xz\n-sha512  7438a572651dc77c1fd749879abccdc9a245c7b75143668d5561a8e99d41063f042a8eb3f9b931a2a12be1fc3cb9d197eee6794d0702a19e56c20f55acb35a26  xwayland-24.1.9.tar.xz\n+# From https://lists.x.org/archives/xorg-announce/2026-April/003679.html\n+sha256  459762be8ea046c94386687d77a87add6073868bee14f02913eafebb945b7aa0  xwayland-24.1.10.tar.xz\n+sha512  bceba1db7f4d7ac92d2b2a3c8f6f7ab0cc093f396fe89406f8dba25e32ffc3edfa552df246cbfb3b0708c1d28b3e179694d11870b063d5b8f9ab2db9fb861a8f  xwayland-24.1.10.tar.xz\n \n # Locally calculated\n-sha256  abbb7969df55e399e91104ded4d0a20a1b67de7c01138e63d61b7ed4f81fec0d  COPYING\n+sha256  c9f90a6669109aad6c9a7c3b46cc2c574221a73b792afa419336816b49da5c11  COPYING\ndiff --git a/package/x11r7/xwayland/xwayland.mk b/package/x11r7/xwayland/xwayland.mk\nindex d4fd47413f..1c90447aef 100644\n--- a/package/x11r7/xwayland/xwayland.mk\n+++ b/package/x11r7/xwayland/xwayland.mk\n@@ -4,7 +4,7 @@\n #\n ################################################################################\n \n-XWAYLAND_VERSION = 24.1.9\n+XWAYLAND_VERSION = 24.1.10\n XWAYLAND_SOURCE = xwayland-$(XWAYLAND_VERSION).tar.xz\n XWAYLAND_SITE = https://xorg.freedesktop.org/archive/individual/xserver\n XWAYLAND_LICENSE = MIT\n","prefixes":["2/2"]}