xserver/randr
Olivier Fourdan 07203788d3 randr: Check for overflow in RRChangeProviderProperty()
A client might send a request causing an integer overflow when computing
the total size to allocate in RRChangeProviderProperty().

To avoid the issue, check that total length in bytes won't exceed the
maximum integer value.

CVE-2025-49180

This issue was discovered by Nils Emmerich <nemmerich@ernw.de> and
reported by Julian Suleder via ERNW Vulnerability Disclosure.

Signed-off-by: Olivier Fourdan <ofourdan@redhat.com>
Reviewed-by: Peter Hutterer <peter.hutterer@who-t.net>
Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2024>
(cherry picked from commit 3c3a4b767b)
2026-01-25 10:40:02 -08:00
..
meson.build meson: hide C API if Xorg is disabled (like autotools) 2021-03-11 00:22:36 +00:00
randr.c randr: move private definitons from randrstr.h to randrstr_priv.h 2026-01-19 12:32:18 -08:00
randrstr.h randr: move private definitons from randrstr.h to randrstr_priv.h 2026-01-19 12:32:18 -08:00
randrstr_priv.h randr: move private definitons from randrstr.h to randrstr_priv.h 2026-01-19 12:32:18 -08:00
rrcrtc.c randr: fix length checking with bigreq 2026-01-25 10:39:58 -08:00
rrdispatch.c prevent name clash on Windows w/ RT_* defines 2026-01-19 12:48:30 -08:00
rrinfo.c Convert top level extensions to new *allocarray functions 2015-04-21 16:57:08 -07:00
rrlease.c prevent name clash on Windows w/ RT_* defines 2026-01-19 12:48:30 -08:00
rrmode.c randr: fix length checking with bigreq 2026-01-25 10:39:58 -08:00
rrmonitor.c randr: fix length checking with bigreq 2026-01-25 10:39:58 -08:00
rroutput.c randr: move private definitons from randrstr.h to randrstr_priv.h 2026-01-19 12:32:18 -08:00
rrpointer.c randr: Fix logic in RRPointerToNearestCrtc 2014-07-30 14:40:17 -07:00
rrproperty.c randr: fix length checking with bigreq 2026-01-25 10:39:58 -08:00
rrprovider.c randr: fix unconditional byte-swap in ProcRRGetProviderInfo() 2026-01-25 10:40:01 -08:00
rrproviderproperty.c randr: Check for overflow in RRChangeProviderProperty() 2026-01-25 10:40:02 -08:00
rrscreen.c randr: move private definitons from randrstr.h to randrstr_priv.h 2026-01-19 12:32:18 -08:00
rrsdispatch.c randr: drop swapping request length fields 2026-01-25 10:39:59 -08:00
rrtransform.c randr: Silence -Wshift-negative-value warnings 2015-10-19 11:51:52 -04:00
rrtransform.h Drop trailing whitespaces 2014-11-12 10:25:00 +10:00
rrxinerama.c randr: drop now obsolete swap procs 2026-01-25 10:39:59 -08:00