xserver/xfixes
Olivier Fourdan 721d4ff4e5 xfixes: Check request length for SetClientDisconnectMode
The handler of XFixesSetClientDisconnectMode does not check the client
request length.

A client could send a shorter request and read data from a former
request.

Fix the issue by checking the request size matches.

CVE-2025-49177

This issue was discovered by Nils Emmerich <nemmerich@ernw.de> and
reported by Julian Suleder via ERNW Vulnerability Disclosure.

Fixes: e167299f6 - xfixes: Add ClientDisconnectMode
Signed-off-by: Olivier Fourdan <ofourdan@redhat.com>
Reviewed-by: Peter Hutterer <peter.hutterer@who-t.net>
Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2024>
(cherry picked from commit ab02fb96b1)
2026-01-25 10:40:01 -08:00
..
cursor.c xfixes: drop swapping request length fields 2026-01-25 10:39:58 -08:00
disconnect.c xfixes: Check request length for SetClientDisconnectMode 2026-01-25 10:40:01 -08:00
meson.build xfixes: Add ClientDisconnectMode 2021-06-07 17:28:05 +02:00
region.c xfixes: drop swapping request length fields 2026-01-25 10:39:58 -08:00
saveset.c xfixes: drop swapping request length fields 2026-01-25 10:39:58 -08:00
select.c xfixes: drop swapping request length fields 2026-01-25 10:39:58 -08:00
xfixes.c xfixes: drop swapping request length fields 2026-01-25 10:39:58 -08:00
xfixes.h xfixes: Unexport xfixes.h 2015-07-08 16:40:58 -04:00
xfixesint.h Remove "All rights reserved" from Oracle copyright notices 2023-02-25 09:40:41 -08:00