ChangeLog for: 2025-06-17 23:29:56
a/pam-1.7.1-x86_64-1.txz: Upgraded.
d/git-2.50.0-x86_64-1.txz: Upgraded.
l/adwaita-icon-theme-48.1-noarch-1.txz: Upgraded.
l/enchant-2.8.8-x86_64-1.txz: Upgraded.
l/libogg-1.3.6-x86_64-1.txz: Upgraded.
l/liburing-2.11-x86_64-1.txz: Upgraded.
l/python-smartypants-2.0.2-x86_64-1.txz: Upgraded.
n/nghttp2-1.66.0-x86_64-1.txz: Upgraded.
x/fcitx5-5.1.13-x86_64-1.txz: Upgraded.
x/fcitx5-anthy-5.1.7-x86_64-1.txz: Upgraded.
x/fcitx5-chinese-addons-5.1.9-x86_64-1.txz: Upgraded.
x/fcitx5-gtk-5.1.4-x86_64-1.txz: Upgraded.
x/fcitx5-hangul-5.1.7-x86_64-1.txz: Upgraded.
x/fcitx5-kkc-5.1.7-x86_64-1.txz: Upgraded.
x/fcitx5-m17n-5.1.4-x86_64-1.txz: Upgraded.
x/fcitx5-qt-5.1.10-x86_64-1.txz: Upgraded.
x/fcitx5-sayura-5.1.4-x86_64-1.txz: Upgraded.
x/fcitx5-table-extra-5.1.8-x86_64-1.txz: Upgraded.
x/fcitx5-table-other-5.1.5-x86_64-1.txz: Upgraded.
x/fcitx5-unikey-5.1.7-x86_64-1.txz: Upgraded.
x/ibus-table-1.17.14-x86_64-1.txz: Upgraded.
x/libime-1.1.11-x86_64-1.txz: Upgraded.
x/xf86-video-vmware-13.4.0-x86_64-2.txz: Removed.
Changes to Mesa have broken this driver, probably for good. Let's remove it
so that the modesetting driver will be used instead.
Thanks to TedCHoward.
x/xorg-server-21.1.17-x86_64-1.txz: Upgraded.
This update fixes security issues:
Out-of-bounds access in X Rendering extension (Animated cursors).
Integer overflow in Big Requests Extension.
Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode).
Unprocessed client request via bytes to ignore.
Integer overflow in X Record extension.
Integer overflow in RandR extension (RRChangeProviderProperty).
These issues were discovered by Nils Emmerich and reported by Julian Suleder
via ERNW Vulnerability Disclosure.
For more information, see:
https://lists.x.org/archives/xorg-announce/2025-June/003609.html
https://lists.x.org/archives/xorg/2025-June/062055.html
https://www.cve.org/CVERecord?id=CVE-2025-49175
https://www.cve.org/CVERecord?id=CVE-2025-49176
https://www.cve.org/CVERecord?id=CVE-2025-49177
https://www.cve.org/CVERecord?id=CVE-2025-49178
https://www.cve.org/CVERecord?id=CVE-2025-49179
https://www.cve.org/CVERecord?id=CVE-2025-49180
(* Security fix *)
x/xorg-server-xephyr-21.1.17-x86_64-1.txz: Upgraded.
x/xorg-server-xnest-21.1.17-x86_64-1.txz: Upgraded.
x/xorg-server-xvfb-21.1.17-x86_64-1.txz: Upgraded.
x/xorg-server-xwayland-24.1.7-x86_64-1.txz: Upgraded.
This update fixes security issues:
Out-of-bounds access in X Rendering extension (Animated cursors).
Integer overflow in Big Requests Extension.
Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode).
Unprocessed client request via bytes to ignore.
Integer overflow in X Record extension.
Integer overflow in RandR extension (RRChangeProviderProperty).
These issues were discovered by Nils Emmerich and reported by Julian Suleder
via ERNW Vulnerability Disclosure.
For more information, see:
https://lists.x.org/archives/xorg-announce/2025-June/003610.html
https://lists.x.org/archives/xorg/2025-June/062055.html
https://www.cve.org/CVERecord?id=CVE-2025-49175
https://www.cve.org/CVERecord?id=CVE-2025-49176
https://www.cve.org/CVERecord?id=CVE-2025-49177
https://www.cve.org/CVERecord?id=CVE-2025-49178
https://www.cve.org/CVERecord?id=CVE-2025-49179
https://www.cve.org/CVERecord?id=CVE-2025-49180
(* Security fix *)