Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libXtst for openSUSE:Factory checked 
in at 2026-09-28 10:34:58
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libXtst (Old)
 and      /work/SRC/openSUSE:Factory/.libXtst.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libXtst"

Mon Sep 28 10:34:58 2026 rev:14 rq:1380034 version:1.2.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/libXtst/libXtst.changes  2024-08-06 
09:07:36.495923020 +0200
+++ /work/SRC/openSUSE:Factory/.libXtst.new.383539/libXtst.changes      
2026-09-28 10:35:00.508190045 +0200
@@ -1,0 +2,7 @@
+Wed Sep 23 19:55:28 UTC 2026 - Stefan Dirsch <[email protected]>
+
+- 
0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch
+  * Out-of-bounds read in libXtst's RECORD reply parser
+    (boo#1281665, CVE-2026-94286)
+
+-------------------------------------------------------------------

New:
----
  
0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch

----------(New B)----------
  New:
- 
0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch
  * Out-of-bounds read in libXtst's RECORD reply parser
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libXtst.spec ++++++
--- /var/tmp/diff_new_pack.iLmnxa/_old  2026-09-28 10:35:01.303223355 +0200
+++ /var/tmp/diff_new_pack.iLmnxa/_new  2026-09-28 10:35:01.305223438 +0200
@@ -1,7 +1,7 @@
 #
 # spec file for package libXtst
 #
-# Copyright (c) 2024 SUSE LLC
+# Copyright (c) 2026 SUSE LLC and contributors
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -29,6 +29,7 @@
 #Git-Web:      http://cgit.freedesktop.org/xorg/lib/libXtst/
 Source:         
http://xorg.freedesktop.org/releases/individual/lib/%{name}-%{version}.tar.xz
 Source1:        baselibs.conf
+Patch1:         
0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch
 BuildRoot:      %{_tmppath}/%{name}-%{version}-build
 #git#BuildRequires:    autoconf >= 2.60, automake, libtool
 BuildRequires:  fdupes
@@ -83,7 +84,7 @@
 in %lname.
 
 %prep
-%setup -q
+%autosetup -p1
 
 %build
 %configure --docdir=%_docdir/%name --disable-static

++++++ 
0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch
 ++++++
>From 16023c86070e6af9407330deea3938fcef75815b Mon Sep 17 00:00:00 2001
From: Olivier Fourdan <[email protected]>
Date: Fri, 31 Jul 2026 11:24:59 +0200
Subject: [PATCH] parse_reply_call_callback: check element size against
 remaining reply buffer

The previous INT_MAX-oriented check only caught arithmetic overflow, not
an oversized datum_bytes claimed by a RECORD reply element.

A malicious server could hand the RECORD callback a pointer/length pair
whose advertised length exceeds the actual reply buffer.

Found by AISLE in partnership with Red Hat

AISLE-Report-PSIRTSUPT-16762

CVE-2026-94286

Reported-by: Aisle Research
Signed-off-by: Olivier Fourdan <[email protected]>
Co-authored-by: AI
---
 src/XRecord.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/src/XRecord.c b/src/XRecord.c
index 32c17bb..656f377 100644
--- a/src/XRecord.c
+++ b/src/XRecord.c
@@ -726,10 +726,12 @@ parse_reply_call_callback(
 {
     XRecordInterceptData *data;
     unsigned int current_index;
+    unsigned int end;
     int datum_bytes = 0;
 
     /* call the callback for each protocol element in the reply */
     current_index = 0;
+    end = rep->length << 2;
     do {
        data = alloc_inter_data(info);
        if (!data)
@@ -839,10 +841,10 @@ parse_reply_call_callback(
        }
 
        if (datum_bytes > 0) {
-           if (INT_MAX - datum_bytes < (rep->length << 2) - current_index) {
+           if ((unsigned int)datum_bytes > end - current_index) {
                fprintf(stderr,
-                       "XRecord: %lu-byte reply claims %d-byte element (seq 
%lu)\n",
-                       (unsigned long)rep->length << 2, current_index + 
datum_bytes,
+                       "XRecord: %u-byte reply claims %u-byte element (seq 
%lu)\n",
+                       end, current_index + (unsigned int)datum_bytes,
                        dpy->last_request_read);
                goto out;
            }
@@ -861,7 +863,7 @@ parse_reply_call_callback(
        (*callback)(closure, data);
 
        current_index += datum_bytes;
-    } while (current_index<rep->length<<2);
+    } while (current_index < end);
 
     if (rep->category == XRecordEndOfData)
        return End;
-- 
2.51.0

Reply via email to