security update regression tracking bug

Bug #2051536 reported by Marc Deslauriers
262
This bug affects 2 people
Affects Status Importance Assigned to Milestone
xorg-server (Ubuntu)
Fix Released
Undecided
Unassigned
Focal
Fix Released
Undecided
Marc Deslauriers
Jammy
Fix Released
Undecided
Marc Deslauriers
Mantic
Fix Released
Undecided
Marc Deslauriers
Noble
Fix Released
Undecided
Unassigned
xwayland (Ubuntu)
Fix Released
Undecided
Unassigned
Focal
Invalid
Undecided
Unassigned
Jammy
Fix Released
Undecided
Unassigned
Mantic
Fix Released
Undecided
Unassigned
Noble
Fix Released
Undecided
Unassigned

Bug Description

CVE References

Changed in xorg-server (Ubuntu Noble):
status: New → Fix Released
Changed in xorg-server (Ubuntu Focal):
status: New → In Progress
Changed in xorg-server (Ubuntu Jammy):
status: New → In Progress
Changed in xorg-server (Ubuntu Mantic):
status: New → In Progress
Changed in xorg-server (Ubuntu Focal):
assignee: nobody → Marc Deslauriers (mdeslaur)
Changed in xorg-server (Ubuntu Jammy):
assignee: nobody → Marc Deslauriers (mdeslaur)
Changed in xorg-server (Ubuntu Mantic):
assignee: nobody → Marc Deslauriers (mdeslaur)
Changed in xwayland (Ubuntu Focal):
status: New → Invalid
Changed in xwayland (Ubuntu Mantic):
status: New → Fix Released
Changed in xwayland (Ubuntu Noble):
status: New → Fix Released
Changed in xwayland (Ubuntu Jammy):
status: New → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xorg-server - 2:1.20.13-1ubuntu1~20.04.15

---------------
xorg-server (2:1.20.13-1ubuntu1~20.04.15) focal-security; urgency=medium

  * SECURITY REGRESSION: memory leak due to incomplete fix (LP: #2051536)
    - debian/patches/CVE-2024-21886-3.patch: fix use after free in input
      device shutdown in dix/devices.c.

 -- Marc Deslauriers <email address hidden> Mon, 29 Jan 2024 07:44:21 -0500

Changed in xorg-server (Ubuntu Focal):
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xwayland - 2:22.1.1-1ubuntu0.11

---------------
xwayland (2:22.1.1-1ubuntu0.11) jammy-security; urgency=medium

  * SECURITY REGRESSION: memory leak due to incomplete fix (LP: #2051536)
    - debian/patches/CVE-2024-21886-3.patch: fix use after free in input
      device shutdown in dix/devices.c.

 -- Marc Deslauriers <email address hidden> Mon, 29 Jan 2024 07:51:17 -0500

Changed in xwayland (Ubuntu Jammy):
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xorg-server - 2:21.1.7-3ubuntu2.7

---------------
xorg-server (2:21.1.7-3ubuntu2.7) mantic-security; urgency=medium

  * SECURITY REGRESSION: memory leak due to incomplete fix (LP: #2051536)
    - debian/patches/CVE-2024-21886-3.patch: fix use after free in input
      device shutdown in dix/devices.c.

 -- Marc Deslauriers <email address hidden> Mon, 29 Jan 2024 07:40:13 -0500

Changed in xorg-server (Ubuntu Mantic):
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xorg-server - 2:21.1.4-2ubuntu1.7~22.04.8

---------------
xorg-server (2:21.1.4-2ubuntu1.7~22.04.8) jammy-security; urgency=medium

  * SECURITY REGRESSION: memory leak due to incomplete fix (LP: #2051536)
    - debian/patches/CVE-2024-21886-3.patch: fix use after free in input
      device shutdown in dix/devices.c.

 -- Marc Deslauriers <email address hidden> Mon, 29 Jan 2024 07:43:15 -0500

Changed in xorg-server (Ubuntu Jammy):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.