An update for libX11 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libX11 security update Advisory ID: RHSA-2021:4326-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4326 Issue date: 2021-11-09 CVE Names: CVE-2021-31535 ==================================================================== 1. Summary: An update for libX11 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: The libX11 packages contain the core X11 protocol client library. Security Fix(es): * libX11: missing request length checks (CVE-2021-31535) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1961822 - CVE-2021-31535 libX11: missing requestlength checks 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: libX11-1.6.8-5.el8.src.rpm aarch64: libX11-1.6.8-5.el8.aarch64.rpm libX11-debuginfo-1.6.8-5.el8.aarch64.rpm libX11-debugsource-1.6.8-5.el8.aarch64.rpm libX11-devel-1.6.8-5.el8.aarch64.rpm libX11-xcb-1.6.8-5.el8.aarch64.rpm libX11-xcb-debuginfo-1.6.8-5.el8.aarch64.rpm noarch: libX11-common-1.6.8-5.el8.noarch.rpm ppc64le: libX11-1.6.8-5.el8.ppc64le.rpm libX11-debuginfo-1.6.8-5.el8.ppc64le.rpm libX11-debugsource-1.6.8-5.el8.ppc64le.rpm libX11-devel-1.6.8-5.el8.ppc64le.rpm libX11-xcb-1.6.8-5.el8.ppc64le.rpm libX11-xcb-debuginfo-1.6.8-5.el8.ppc64le.rpm s390x: libX11-1.6.8-5.el8.s390x.rpm libX11-debuginfo-1.6.8-5.el8.s390x.rpm libX11-debugsource-1.6.8-5.el8.s390x.rpm libX11-devel-1.6.8-5.el8.s390x.rpm libX11-xcb-1.6.8-5.el8.s390x.rpm libX11-xcb-debuginfo-1.6.8-5.el8.s390x.rpm x86_64: libX11-1.6.8-5.el8.i686.rpm libX11-1.6.8-5.el8.x86_64.rpm libX11-debuginfo-1.6.8-5.el8.i686.rpm libX11-debuginfo-1.6.8-5.el8.x86_64.rpm libX11-debugsource-1.6.8-5.el8.i686.rpm libX11-debugsource-1.6.8-5.el8.x86_64.rpm libX11-devel-1.6.8-5.el8.i686.rpm libX11-devel-1.6.8-5.el8.x86_64.rpm libX11-xcb-1.6.8-5.el8.i686.rpm libX11-xcb-1.6.8-5.el8.x86_64.rpm libX11-xcb-debuginfo-1.6.8-5.el8.i686.rpm libX11-xcb-debuginfo-1.6.8-5.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-31535 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYYreK9zjgjWX9erEAQhC8w//Ujz6OHnq5956ZCePDTRqMWQdCIibXVhG wYzFnS6AerdBArGJ9XaPLMxF/bCGrD2JzVgneYjT5r/GISsZNh0ZVuMG1Y+lj0ZS IUCGZ6FccdGqPlV+6pYEQye+met57JOvcKyCp6o+cE49EGz/SnSFSBjxFrTxkft5 QpEP8DJP2kfODOtzTFSGrtKQ56zJXr3W4JLrfs6kjz560Wsrng7EnveTQzbVhGx8 mjtLQB4TNIaKTS9vsYLKzA3oEtnWoOn0bXijZ+9ReD8r60nXbCirkOnCus2coyJ5 N8tOWPbQomsYEMGmOabkAhLErwJVTvAX2QS5qHJQzLHnQo1H7PWObkXDf9Vgvyf3 s7TKxmRI6U/zAmbLUG8PnEdXxyzqIYB+Y6DMdqp25RJ2tsDnT1OL2wI/A221WyOE aqZOQYpKq12w8WMenz4rctASUc/Ja1uFUZ1kS+EeL/z0idgV/8FoRA965autTtBp 5O0IwVw1MRBTh/EherYqh2Ge0oBbShbtPcEJsxRL13+mXIpROg5zDiEmdVClHIUT +McwHY5fkGgtVALg6e1XG1uYx7db+feJ36psStsMLwG6eFLXyQP/mbM0y6AfrmOU 5jW49d2e594EHtIBi39nXDvM6eLTDPuV/c8Sb6Vd1RN+690K3iOBpixGxszcf6AD MRViCNNJqPg=G6/f -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libX11 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0807-1 Rating: moderate References: #1182506 Cross-References: CVE-2021-31535 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libX11 fixes the following issues: - CVE-2021-31535: Fixed missing request length checks in libX11 (bsc#1182506). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-807=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): libX11-6-1.6.5-lp152.5.15.1 libX11-6-debuginfo-1.6.5-lp152.5.15.1 libX11-debugsource-1.6.5-lp152.5.15.1 libX11-devel-1.6.5-lp152.5.15.1 libX11-xcb1-1.6.5-lp152.5.15.1 libX11-xcb1-debuginfo-1.6.5-lp152.5.15.1 - openSUSE Leap 15.2 (noarch): libX11-data-1.6.5-lp152.5.15.1 - openSUSE Leap 15.2 (x86_64): libX11-6-32bit-1.6.5-lp152.5.15.1 libX11-6-32bit-debuginfo-1.6.5-lp152.5.15.1 libX11-devel-32bit-1.6.5-lp152.5.15.1 libX11-xcb1-32bit-1.6.5-lp152.5.15.1 libX11-xcb1-32bit-debuginfo-1.6.5-lp152.5.15.1 References: https://www.suse.com/security/cve/CVE-2021-31535.html https://bugzilla.suse.com/1182506 . Addresses a significant vulnerability in libX11 for openSUSE Leap 15.2. Comprehensive update information and guidance for installation provided.. openSUSE Update, libX11 Security Fix, Software Update, System Security, PatchInstallation. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libX11 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1765-1 Rating: moderate References: #1182506 Cross-References: CVE-2021-31535 Affected Products: SUSE MicroOS 5.0 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libX11 fixes the following issues: - CVE-2021-31535: Fixed missing request length checks in libX11 (bsc#1182506). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-1765=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-1765=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-1765=1 Package List: - SUSE MicroOS 5.0 (aarch64 x86_64): libX11-6-1.6.5-3.18.1 libX11-6-debuginfo-1.6.5-3.18.1 libX11-debugsource-1.6.5-3.18.1 libX11-xcb1-1.6.5-3.18.1 libX11-xcb1-debuginfo-1.6.5-3.18.1 - SUSE MicroOS 5.0 (noarch): libX11-data-1.6.5-3.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libX11-6-1.6.5-3.18.1 libX11-6-debuginfo-1.6.5-3.18.1 libX11-debugsource-1.6.5-3.18.1 libX11-devel-1.6.5-3.18.1 libX11-xcb1-1.6.5-3.18.1 libX11-xcb1-debuginfo-1.6.5-3.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3(x86_64): libX11-6-32bit-1.6.5-3.18.1 libX11-6-32bit-debuginfo-1.6.5-3.18.1 libX11-xcb1-32bit-1.6.5-3.18.1 libX11-xcb1-32bit-debuginfo-1.6.5-3.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): libX11-data-1.6.5-3.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libX11-6-1.6.5-3.18.1 libX11-6-debuginfo-1.6.5-3.18.1 libX11-debugsource-1.6.5-3.18.1 libX11-devel-1.6.5-3.18.1 libX11-xcb1-1.6.5-3.18.1 libX11-xcb1-debuginfo-1.6.5-3.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): libX11-6-32bit-1.6.5-3.18.1 libX11-6-32bit-debuginfo-1.6.5-3.18.1 libX11-xcb1-32bit-1.6.5-3.18.1 libX11-xcb1-32bit-debuginfo-1.6.5-3.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (noarch): libX11-data-1.6.5-3.18.1 References: https://www.suse.com/security/cve/CVE-2021-31535.html https://bugzilla.suse.com/1182506 . SUSE Security Patch for libX11 resolves absent request length verifications, assigned a moderate risk level. Stay informed!. libX11 Update, SUSE Security Advisory, Request Length Issues. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libX11 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1766-1 Rating: moderate References: #1182506 Cross-References: CVE-2021-31535 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libX11 fixes the following issues: - CVE-2021-31535: Fixed missing request length checks in libX11 (bsc#1182506). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-1766=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-1766=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libX11-debugsource-1.6.2-12.18.1 libX11-devel-1.6.2-12.18.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libX11-6-1.6.2-12.18.1 libX11-6-debuginfo-1.6.2-12.18.1 libX11-debugsource-1.6.2-12.18.1 libX11-xcb1-1.6.2-12.18.1 libX11-xcb1-debuginfo-1.6.2-12.18.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libX11-6-32bit-1.6.2-12.18.1 libX11-6-debuginfo-32bit-1.6.2-12.18.1 libX11-xcb1-32bit-1.6.2-12.18.1 libX11-xcb1-debuginfo-32bit-1.6.2-12.18.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): libX11-data-1.6.2-12.18.1 References: https://www.suse.com/security/cve/CVE-2021-31535.html https://bugzilla.suse.com/1182506 . Ubuntu Security Patch for libX11 tackles severe vulnerabilities with the installation guide supplied. Take prompt action!. SUSE Linux Update, libX11 Security Update, SUSE Vulnerability Fix. . LinuxSecurity.com Team
New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libX11 (SSA:2021-139-01) New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/libX11-1.7.1-i586-1_slack14.2.txz: Upgraded. This update fixes missing request length checks in libX11 that can lead to the emission of extra X protocol requests to the X server. For more information, see: https://lists.x.org/archives/xorg-announce/2021-May/003088.html https://www.cve.org/CVERecord?id=CVE-2021-31535 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: 037e061214b75602fecda02dbeff4594 libX11-1.7.1-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 2d361c4a57965f7717c6baeeb64bfbdc libX11-1.7.1-x86_64-1_slack14.0.txz Slackware 14.1 package: 2d248166e3300b2eddf1bf7cdfd9c48e libX11-1.7.1-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 1cbc196fc2b572d9ef1d782780e715c4 libX11-1.7.1-x86_64-1_slack14.1.txz Slackware 14.2 package: e7a8f6730ee2a9f0c1d1b882ef19a328 libX11-1.7.1-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 93c50f408507ca0ec710ec0652911fc5 libX11-1.7.1-x86_64-1_slack14.2.txz Slackware -current package: c4e7afb55aa5cbac724d078bac62d48e x/libX11-1.7.1-i586-1.txz Slackware x86_64 -current package: 4c6d385206e5c2ba7614b1301b850115 x/libX11-1.7.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libX11-1.7.1-i586-1_slack14.2.txz +-----+ . Recent updates to the libX11 packages for Slackware address a significant security vulnerability, enhancing overall system safety and integrity.. libX11,Slackware Security,Software Update. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.