* bsc#1190486 Cross-References: * CVE-2021-3782 . # Security update for wayland Announcement ID: SUSE-SU-2023:1864-1 Rating: important References: * bsc#1190486 Cross-References: * CVE-2021-3782 CVSS scores: * CVE-2021-3782 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2021-3782 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for wayland fixes the following issues: * CVE-2021-3782: Fixed a reference-count overflow in libwayland-server SHM handling. (bsc#1190486) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2023-1864=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-1864=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-1864=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-1864=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libwayland-cursor0-debuginfo-1.13.0-3.3.1 * wayland-devel-1.13.0-3.3.1 * libwayland-client0-debuginfo-1.13.0-3.3.1 * libwayland-server0-debuginfo-1.13.0-3.3.1 * libwayland-server0-1.13.0-3.3.1 * libwayland-cursor0-1.13.0-3.3.1 * wayland-debugsource-1.13.0-3.3.1 * libwayland-client0-1.13.0-3.3.1 * wayland-devel-debuginfo-1.13.0-3.3.1 * SUSE LinuxEnterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libwayland-client0-debuginfo-1.13.0-3.3.1 * wayland-debugsource-1.13.0-3.3.1 * libwayland-client0-1.13.0-3.3.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libwayland-client0-debuginfo-1.13.0-3.3.1 * wayland-debugsource-1.13.0-3.3.1 * libwayland-client0-1.13.0-3.3.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libwayland-client0-debuginfo-1.13.0-3.3.1 * wayland-debugsource-1.13.0-3.3.1 * libwayland-client0-1.13.0-3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2021-3782.html * https://bugzilla.suse.com/show_bug.cgi?id=1190486 . Patch resolves critical reference-count overflow vulnerability in Wayland. This is a significant security update for impacted SUSE distributions.. wayland security update,suse linux patch,reference-count overflow,security fix. . Severity: Important. LinuxSecurity.com Team
An update for wayland is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: wayland security, bug fix, and enhancement update Advisory ID: RHSA-2023:2786-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2786 Issue date: 2023-05-16 CVE Names: CVE-2021-3782 ==================================================================== 1. Summary: An update for wayland is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Wayland is a protocol for a compositor to talk to its clients, as well as a C library implementation of that protocol. The compositor can be a standalone display server running on Linux kernel modesetting and evdev input devices, an X application, or a wayland client itself. The clients can be traditional applications, X servers (rootless or fullscreen) or other display servers. The following packages have been upgraded to a later upstream version: wayland (1.21.0). (BZ#2137625) Security Fix(es): * wayland: libwayland-server wl_shm reference-count overflow (CVE-2021-3782) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.8 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2002627 - CVE-2021-3782 wayland: libwayland-server wl_shm reference-count overflow 2137625 - Rebase wayland to 1.21 in el8 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: wayland-1.21.0-1.el8.src.rpm aarch64: libwayland-client-1.21.0-1.el8.aarch64.rpm libwayland-client-debuginfo-1.21.0-1.el8.aarch64.rpm libwayland-cursor-1.21.0-1.el8.aarch64.rpm libwayland-cursor-debuginfo-1.21.0-1.el8.aarch64.rpm libwayland-egl-1.21.0-1.el8.aarch64.rpm libwayland-egl-debuginfo-1.21.0-1.el8.aarch64.rpm libwayland-server-1.21.0-1.el8.aarch64.rpm libwayland-server-debuginfo-1.21.0-1.el8.aarch64.rpm wayland-debuginfo-1.21.0-1.el8.aarch64.rpm wayland-debugsource-1.21.0-1.el8.aarch64.rpm wayland-devel-1.21.0-1.el8.aarch64.rpm wayland-devel-debuginfo-1.21.0-1.el8.aarch64.rpm ppc64le: libwayland-client-1.21.0-1.el8.ppc64le.rpm libwayland-client-debuginfo-1.21.0-1.el8.ppc64le.rpm libwayland-cursor-1.21.0-1.el8.ppc64le.rpm libwayland-cursor-debuginfo-1.21.0-1.el8.ppc64le.rpm libwayland-egl-1.21.0-1.el8.ppc64le.rpm libwayland-egl-debuginfo-1.21.0-1.el8.ppc64le.rpm libwayland-server-1.21.0-1.el8.ppc64le.rpm libwayland-server-debuginfo-1.21.0-1.el8.ppc64le.rpm wayland-debuginfo-1.21.0-1.el8.ppc64le.rpm wayland-debugsource-1.21.0-1.el8.ppc64le.rpm wayland-devel-1.21.0-1.el8.ppc64le.rpm wayland-devel-debuginfo-1.21.0-1.el8.ppc64le.rpm s390x: libwayland-client-1.21.0-1.el8.s390x.rpm libwayland-client-debuginfo-1.21.0-1.el8.s390x.rpm libwayland-cursor-1.21.0-1.el8.s390x.rpm libwayland-cursor-debuginfo-1.21.0-1.el8.s390x.rpm libwayland-egl-1.21.0-1.el8.s390x.rpm libwayland-egl-debuginfo-1.21.0-1.el8.s390x.rpm libwayland-server-1.21.0-1.el8.s390x.rpm libwayland-server-debuginfo-1.21.0-1.el8.s390x.rpm wayland-debuginfo-1.21.0-1.el8.s390x.rpm wayland-debugsource-1.21.0-1.el8.s390x.rpm wayland-devel-1.21.0-1.el8.s390x.rpm wayland-devel-debuginfo-1.21.0-1.el8.s390x.rpm x86_64: libwayland-client-1.21.0-1.el8.i686.rpm libwayland-client-1.21.0-1.el8.x86_64.rpm libwayland-client-debuginfo-1.21.0-1.el8.i686.rpm libwayland-client-debuginfo-1.21.0-1.el8.x86_64.rpm libwayland-cursor-1.21.0-1.el8.i686.rpm libwayland-cursor-1.21.0-1.el8.x86_64.rpm libwayland-cursor-debuginfo-1.21.0-1.el8.i686.rpm libwayland-cursor-debuginfo-1.21.0-1.el8.x86_64.rpm libwayland-egl-1.21.0-1.el8.i686.rpm libwayland-egl-1.21.0-1.el8.x86_64.rpm libwayland-egl-debuginfo-1.21.0-1.el8.i686.rpm libwayland-egl-debuginfo-1.21.0-1.el8.x86_64.rpm libwayland-server-1.21.0-1.el8.i686.rpm libwayland-server-1.21.0-1.el8.x86_64.rpm libwayland-server-debuginfo-1.21.0-1.el8.i686.rpm libwayland-server-debuginfo-1.21.0-1.el8.x86_64.rpm wayland-debuginfo-1.21.0-1.el8.i686.rpm wayland-debuginfo-1.21.0-1.el8.x86_64.rpm wayland-debugsource-1.21.0-1.el8.i686.rpm wayland-debugsource-1.21.0-1.el8.x86_64.rpm wayland-devel-1.21.0-1.el8.i686.rpm wayland-devel-1.21.0-1.el8.x86_64.rpm wayland-devel-debuginfo-1.21.0-1.el8.i686.rpm wayland-devel-debuginfo-1.21.0-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-3782 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.8_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZGNu0NzjgjWX9erEAQhUmg/8Da+VioYQjcW8BN65bynHVZiYWk2/m3u2 3mhpyFVnHGCai1YZ6IIx6e2XKaaWTD/8dFykp/M0Ol7/FcE97KrH9MPJdEJlrNr8 wcOkCE+uPKywi70uV43by6aVqSYMTpuH7DtcSA2KZ88N6Q3L3IPRqxxpqRxrM5iz XRGCvePyAozIXx13qa6D9jJeBH5vD9ellhbnRYB5ZJFktwQzkjfvaQjNc4d0jSLi jOHX7K+wrlBSX4fuTckdzd572IC/FEqjI69nJsO5USpg/nzeWrY4p9tA7v/Bd1JR xy5fLSqB0JRpCpU6bRqPbpgGUaJSPaOcuVHfTveVrxOG+9XEoe+hN/poRM9ahjep haYJahgA4t9bkaXbwjQq9g87eXz7xUhrtoc9Y7WHPrTxNg+oMbPg/0J5guOXofPC vbF1Kv86KlOQuaYChxKYGXswHxDd8sW07R+70+yYFpfOmDY8uCA1ROmnXSmYpAAV KCaos7lJL6Ctv+o1d9fumAnTMsC/UqnjJqXaX1S+IVVsbWo9gvnoJ0YzahZ4dEUU 6M+p36dZ+TaLep2B8UkrYgHQqfqA9hJTTQUiguM1biP3sYjjeTdtes5CS/TOBalJ EQQiTbN0I/zqBrfjPGtDFig4LE+RdXBw5Y9HYs93J1w76C5j3WZ6ZuaBosgNrqkW fpXPl56mGZY=fZCa -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count is maintained as an int; on LP64 systems this can cause the reference count to overflow if the client creates a large number of wl_shm buffer objects, or if it can coerce the server to create a large number of external . MGASA-2022-0418 - Updated wayland packages fix security vulnerability Publication date: 13 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0418.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3782 An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count is maintained as an int; on LP64 systems this can cause the reference count to overflow if the client creates a large number of wl_shm buffer objects, or if it can coerce the server to create a large number of external references to the buffer storage. With the reference count overflowing, a use-after-free can be constructed on the wl_shm_pool tracking structure, where values may be incremented or decremented; it may also be possible to construct a limited oracle to leak 4 bytes of server-side memory to the attacking client at a time. (CVE-2021-3782) References: - https://bugs.mageia.org/show_bug.cgi?id=30855 - https://ubuntu.com/security/notices/USN-5614-1 - https://www.cve.org/CVERecord?id=CVE-2021-3782 SRPMS: - 8/core/wayland-1.18.0-3.1.mga8 . Recent updates to Wayland packages in Mageia address a severe buffer overflow vulnerability that could result in memory leaks.. Mageia Security Advisory, Wayland Buffer Overflow, Critical Update. . Severity: Critical. LinuxSecurity.com Team
Wayland could be made to crash or run programs.. =========================================================================Ubuntu Security Notice USN-5614-2 October 03, 2022 wayland vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Wayland could be made to crash or run programs. Software Description: - wayland: Wayland compositor infrastructure Details: USN-5614-1 fixed a vulnerability in Wayland. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: It was discovered that Wayland incorrectly handled reference counting certain objects. An attacker could use this issue to cause Wayland to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libwayland-bin 1.12.0-1~ubuntu16.04.3+esm1 libwayland-client0 1.12.0-1~ubuntu16.04.3+esm1 libwayland-cursor0 1.12.0-1~ubuntu16.04.3+esm1 libwayland-server0 1.12.0-1~ubuntu16.04.3+esm1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5614-2 https://ubuntu.com/security/notices/USN-5614-1 CVE-2021-3782 . A vulnerability found in Wayland on Ubuntu 16.04 ESM may cause unexpected crashes or allow unauthorized application execution. It's crucial to apply updates.. Wayland Vulnerability, Ubuntu Advisory, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
Wayland could be made to crash or run programs.. =========================================================================Ubuntu Security Notice USN-5614-1 September 15, 2022 wayland vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Wayland could be made to crash or run programs. Software Description: - wayland: Wayland compositor infrastructure Details: It was discovered that Wayland incorrectly handled reference counting certain objects. An attacker could use this issue to cause Wayland to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: libwayland-bin 1.20.0-1ubuntu0.1 libwayland-client0 1.20.0-1ubuntu0.1 libwayland-egl1 1.20.0-1ubuntu0.1 libwayland-server0 1.20.0-1ubuntu0.1 Ubuntu 20.04 LTS: libwayland-bin 1.18.0-1ubuntu0.1 libwayland-client0 1.18.0-1ubuntu0.1 libwayland-egl1 1.18.0-1ubuntu0.1 libwayland-server0 1.18.0-1ubuntu0.1 Ubuntu 18.04 LTS: libwayland-bin 1.16.0-1ubuntu1.1~18.04.4 libwayland-client0 1.16.0-1ubuntu1.1~18.04.4 libwayland-egl1 1.16.0-1ubuntu1.1~18.04.4 libwayland-server0 1.16.0-1ubuntu1.1~18.04.4 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5614-1 CVE-2021-3782 Package Information: https://launchpad.net/ubuntu/+source/wayland/1.20.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/wayland/1.18.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/wayland/1.16.0-1ubuntu1.1~18.04.4 .Enhance your Ubuntu installation by applying the latest updates to address the Wayland security flaw, thus safeguarding against possible attacks and maintaining robust functionality.. Wayland Exploit, Ubuntu 22.04 LTS, Denial Of Service Threat, Security Fix. . Severity: Critical. LinuxSecurity.com Team
- New upstream update (101.0) ---- - Fixed missing popups in some scenarios on Wayland (https://bugzilla.mozilla.org/show_bug.cgi?id=1771104). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-080ea50338 2022-06-04 01:15:43.514032 --------------------------------------------------------------------------------Name : firefox Product : Fedora 36 Version : 101.0 Release : 1.fc36 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - New upstream update (101.0) ---- - Fixed missing popups in some scenarios on Wayland (https://bugzilla.mozilla.org/show_bug.cgi?id=1771104) --------------------------------------------------------------------------------ChangeLog: * Mon May 30 2022 Martin Stransky - 101.0-1 - Updated to 101.0 * Wed May 25 2022 Martin Stransky - 100.0.2-2 - Added fix for mzbz#1771104 --------------------------------------------------------------------------------References: [ 1 ] Bug #2092037 - Firefox 101 released - multiple security fixes https://bugzilla.redhat.com/show_bug.cgi?id=2092037 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-080ea50338' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Updated to new upstream (88.0.1) ---- - Fixed WebRTC indicator (mozbz#1705048). ---- - Enable Wayland backend on Plasma/KDE by default (rhbz#1922608) ---- Fixed pointer locking issues under Wayland which affects WebGL applications/games (see https://bugzilla.mozilla.org/show_bug.cgi?id=1580595#c23). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-4f06d202d4 2021-05-20 01:26:49.877963 --------------------------------------------------------------------------------Name : firefox Product : Fedora 32 Version : 88.0.1 Release : 1.fc32 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - Updated to new upstream (88.0.1) ---- - Fixed WebRTC indicator (mozbz#1705048). ---- - Enable Wayland backend on Plasma/KDE by default (rhbz#1922608) ---- Fixed pointer locking issues under Wayland which affects WebGL applications/games (see https://bugzilla.mozilla.org/show_bug.cgi?id=1580595#c23) --------------------------------------------------------------------------------ChangeLog: * Mon May 10 2021 Martin Stransky - 88.0.1-1 - Updated to latest upstream (88.0.1) * Tue May 4 2021 Martin Stransky - 88.0-8 - Added fix for mozbz#1705048. * Fri Apr 30 2021 Martin Stransky - 88.0-7 - Added pciutils-libs req (rhbz#1955338) - Enabled Wayland on KDE (rhbz#1922608) * Tue Apr 27 2021 Martin Stransky - 88.0-6 - Test fix. * Fri Apr 23 2021 Martin Stransky - 88.0-5 - Added fix for mozbz#1580595 - mouse pointer lock. - Another test update. --------------------------------------------------------------------------------References: [ 1 ] Bug #1922608 - [KDE/Plasma] Ship default Firefox Wayland backend on Fedora34/KDE https://bugzilla.redhat.com/show_bug.cgi?id=1922608 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-4f06d202d4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Updated to new upstream (69.0.1) - Wayland rendering fixes ---- - The update to 69.0.1 - Fix flickering issues - Fix disappearing webrtc dialogs ---- - Fixed rendering artifacts on Wayland backend. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-7f7bace5b4 2019-09-21 00:00:44.539947 --------------------------------------------------------------------------------Name : firefox Product : Fedora 31 Version : 69.0.1 Release : 3.fc31 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - Updated to new upstream (69.0.1) - Wayland rendering fixes ---- - The update to 69.0.1 - Fix flickering issues - Fix disappearing webrtc dialogs ---- -Fixed rendering artifacts on Wayland backend --------------------------------------------------------------------------------References: [ 1 ] Bug #1748442 - Firefox 69.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1748442 [ 2 ] Bug #1751372 - [Wayland] [regression] After updating to version 69, switching between tabs doesn't always update the window's contents https://bugzilla.redhat.com/show_bug.cgi?id=1751372 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-7f7bace5b4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.