ChangeLog for: 2025-10-30 00:07:37
a/kernel-firmware-20251029_bfc8430-noarch-1.txz: Upgraded.
a/kernel-generic-6.12.56-x86_64-1.txz: Upgraded.
d/kernel-headers-6.12.56-x86-1.txz: Upgraded.
k/kernel-source-6.12.56-noarch-1.txz: Upgraded.
l/nodejs-22.21.1-x86_64-1.txz: Upgraded.
l/python-pybind11-3.0.1-x86_64-2.txz: Rebuilt.
Add symlinks to cmake, include, and pkgconfig files.
Thanks to chrisVV.
n/fetchmail-6.6.0-x86_64-1.txz: Upgraded.
n/nghttp3-1.12.0-x86_64-2.txz: Rebuilt.
Respect $LIBDIRSUFFIX when installing cmake files.
x/xorg-server-21.1.20-x86_64-1.txz: Upgraded.
This update fixes security issues:
Use-after-free in XPresentNotify structures creation.
Use-after-free in Xkb client resource removal.
Value overflow in Xkb extension XkbSetCompatMap().
These issues were found by Jan-Niklas Sohn working with Trend Micro Zero
Day Initiative.
For more information, see:
https://lists.x.org/archives/xorg-announce/2025-October/003635.html
https://www.cve.org/CVERecord?id=CVE-2025-62229
https://www.cve.org/CVERecord?id=CVE-2025-62230
https://www.cve.org/CVERecord?id=CVE-2025-62231
(* Security fix *)
x/xorg-server-xephyr-21.1.20-x86_64-1.txz: Upgraded.
x/xorg-server-xnest-21.1.20-x86_64-1.txz: Upgraded.
x/xorg-server-xvfb-21.1.20-x86_64-1.txz: Upgraded.
x/xorg-server-xwayland-24.1.9-x86_64-1.txz: Upgraded.
This update fixes security issues:
Use-after-free in XPresentNotify structures creation.
Use-after-free in Xkb client resource removal.
Value overflow in Xkb extension XkbSetCompatMap().
These issues were found by Jan-Niklas Sohn working with Trend Micro Zero
Day Initiative.
For more information, see:
https://lists.x.org/archives/xorg-announce/2025-October/003635.html
https://www.cve.org/CVERecord?id=CVE-2025-62229
https://www.cve.org/CVERecord?id=CVE-2025-62230
https://www.cve.org/CVERecord?id=CVE-2025-62231
(* Security fix *)
extra/tigervnc/tigervnc-1.15.0-x86_64-5.txz: Rebuilt.
Rebase on xorg-server-21.1.20.
Fixes security issues in xorg-server:
Use-after-free in XPresentNotify structures creation.
Use-after-free in Xkb client resource removal.
Value overflow in Xkb extension XkbSetCompatMap().
These issues were found by Jan-Niklas Sohn working with Trend Micro Zero
Day Initiative.
For more information, see:
https://lists.x.org/archives/xorg-announce/2025-October/003635.html
https://www.cve.org/CVERecord?id=CVE-2025-62229
https://www.cve.org/CVERecord?id=CVE-2025-62230
https://www.cve.org/CVERecord?id=CVE-2025-62231
(* Security fix *)
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/linux-6.17.x/kernel-generic-6.17.6-x86_64-1.txz: Upgraded.
testing/packages/linux-6.17.x/kernel-headers-6.17.6-x86-1.txz: Upgraded.
testing/packages/linux-6.17.x/kernel-source-6.17.6-noarch-1.txz: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.