From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) Subject: Re: [PATCH 0/8] Xorg security updates for the master branch Date: Wed, 05 Oct 2016 23:17:20 +0200 Message-ID: <87shsa5wdb.fsf@gnu.org> References: Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:36592) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1brtZD-00060g-0c for guix-devel@gnu.org; Wed, 05 Oct 2016 17:17:31 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1brtZ7-0003OQ-2g for guix-devel@gnu.org; Wed, 05 Oct 2016 17:17:29 -0400 In-Reply-To: (Leo Famulari's message of "Wed, 5 Oct 2016 13:55:53 -0400") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org Leo Famulari skribis: > There is an Xorg security advisory: > https://lists.freedesktop.org/archives/xorg/2016-October/058344.html > > This patch series applies the patches recommended by upstream using > grafts. > > Leo Famulari (8): > gnu: libx11: Fix CVE-2016-{7942,7943}. > gnu: libxfixes: Fix CVE-2016-7944. > gnu: libxi: Fix CVE-2016-{7945,7946}. > gnu: libxrandr: Fix CVE-2016-{7947,7948}. > gnu: libxrender: Fix CVE-2016-{7949,7950}. > gnu: libxtst: Fix CVE-2016-{7951,7952}. > gnu: libxv: Fix CVE-2016-5407. > gnu: libxvmc: Fix CVE-2016-7953. This all LGTM. I tested by (1) building and a running a couple of grafted X clients talking to my (ungrafted) X server, and (2) building my laptop=E2=80=99s co= nfig with =E2=80=98guix system vm=E2=80=99 and checking that both the X server a= nd typical X clients functioned. So I think this can go in on master. (On core-updates it=E2=80=99s probably best to upgrade these libraries inst= ead of patching them, as you wrote on IRC.) Thanks a lot! Ludo=E2=80=99.