Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libXtst for openSUSE:Factory checked in at 2026-09-28 10:34:58 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libXtst (Old) and /work/SRC/openSUSE:Factory/.libXtst.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libXtst" Mon Sep 28 10:34:58 2026 rev:14 rq:1380034 version:1.2.5 Changes: -------- --- /work/SRC/openSUSE:Factory/libXtst/libXtst.changes 2024-08-06 09:07:36.495923020 +0200 +++ /work/SRC/openSUSE:Factory/.libXtst.new.383539/libXtst.changes 2026-09-28 10:35:00.508190045 +0200 @@ -1,0 +2,7 @@ +Wed Sep 23 19:55:28 UTC 2026 - Stefan Dirsch <[email protected]> + +- 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch + * Out-of-bounds read in libXtst's RECORD reply parser + (boo#1281665, CVE-2026-94286) + +------------------------------------------------------------------- New: ---- 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch ----------(New B)---------- New: - 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch * Out-of-bounds read in libXtst's RECORD reply parser ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libXtst.spec ++++++ --- /var/tmp/diff_new_pack.iLmnxa/_old 2026-09-28 10:35:01.303223355 +0200 +++ /var/tmp/diff_new_pack.iLmnxa/_new 2026-09-28 10:35:01.305223438 +0200 @@ -1,7 +1,7 @@ # # spec file for package libXtst # -# Copyright (c) 2024 SUSE LLC +# Copyright (c) 2026 SUSE LLC and contributors # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -29,6 +29,7 @@ #Git-Web: http://cgit.freedesktop.org/xorg/lib/libXtst/ Source: http://xorg.freedesktop.org/releases/individual/lib/%{name}-%{version}.tar.xz Source1: baselibs.conf +Patch1: 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch BuildRoot: %{_tmppath}/%{name}-%{version}-build #git#BuildRequires: autoconf >= 2.60, automake, libtool BuildRequires: fdupes @@ -83,7 +84,7 @@ in %lname. %prep -%setup -q +%autosetup -p1 %build %configure --docdir=%_docdir/%name --disable-static ++++++ 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch ++++++ >From 16023c86070e6af9407330deea3938fcef75815b Mon Sep 17 00:00:00 2001 From: Olivier Fourdan <[email protected]> Date: Fri, 31 Jul 2026 11:24:59 +0200 Subject: [PATCH] parse_reply_call_callback: check element size against remaining reply buffer The previous INT_MAX-oriented check only caught arithmetic overflow, not an oversized datum_bytes claimed by a RECORD reply element. A malicious server could hand the RECORD callback a pointer/length pair whose advertised length exceeds the actual reply buffer. Found by AISLE in partnership with Red Hat AISLE-Report-PSIRTSUPT-16762 CVE-2026-94286 Reported-by: Aisle Research Signed-off-by: Olivier Fourdan <[email protected]> Co-authored-by: AI --- src/XRecord.c | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/src/XRecord.c b/src/XRecord.c index 32c17bb..656f377 100644 --- a/src/XRecord.c +++ b/src/XRecord.c @@ -726,10 +726,12 @@ parse_reply_call_callback( { XRecordInterceptData *data; unsigned int current_index; + unsigned int end; int datum_bytes = 0; /* call the callback for each protocol element in the reply */ current_index = 0; + end = rep->length << 2; do { data = alloc_inter_data(info); if (!data) @@ -839,10 +841,10 @@ parse_reply_call_callback( } if (datum_bytes > 0) { - if (INT_MAX - datum_bytes < (rep->length << 2) - current_index) { + if ((unsigned int)datum_bytes > end - current_index) { fprintf(stderr, - "XRecord: %lu-byte reply claims %d-byte element (seq %lu)\n", - (unsigned long)rep->length << 2, current_index + datum_bytes, + "XRecord: %u-byte reply claims %u-byte element (seq %lu)\n", + end, current_index + (unsigned int)datum_bytes, dpy->last_request_read); goto out; } @@ -861,7 +863,7 @@ parse_reply_call_callback( (*callback)(closure, data); current_index += datum_bytes; - } while (current_index<rep->length<<2); + } while (current_index < end); if (rep->category == XRecordEndOfData) return End; -- 2.51.0
