Activity log for bug #1794690

Date Who What changed Old value New value Message
2018-09-27 07:47:50 Timo Aaltonen bug added bug
2018-09-27 07:47:56 Timo Aaltonen nominated for series Ubuntu Bionic
2018-09-27 07:47:56 Timo Aaltonen bug task added libxkbcommon (Ubuntu Bionic)
2018-09-27 07:48:03 Timo Aaltonen libxkbcommon (Ubuntu): status New Fix Released
2018-09-27 07:48:12 Timo Aaltonen libxkbcommon (Ubuntu Bionic): status New In Progress
2018-09-27 07:48:12 Timo Aaltonen libxkbcommon (Ubuntu Bionic): assignee Timo Aaltonen (tjaalton)
2018-09-27 07:55:16 Timo Aaltonen description [Impact] 0.8.2 has completed the fuzzing work started in 0.8.1, so backport the package from cosmic to fix these CVE's: CVE-2018-15853 CVE-2018-15854 CVE-2018-15855 CVE-2018-15856 CVE-2018-15857 CVE-2018-15858 CVE-2018-15859 CVE-2018-15861 CVE-2018-15862 CVE-2018-15863 CVE-2018-15864. upstream NEWS: libxkbcommon 0.8.2 - 2018-08-05 ================== - Fix various problems found with fuzzing (see commit messages for more details): - Fix a few NULL-dereferences, out-of-bounds access and undefined behavior in the XKB text format parser. libxkbcommon 0.8.1 - 2018-08-03 ================== - Fix various problems found in the meson build (see commit messages for more details): - Fix compilation on Darwin. - Fix compilation of the x11 tests and demos when XCB is installed in a non-standard location. - Fix xkbcommon-x11.pc missing the Requires specification. - Fix various problems found with fuzzing and Coverity (see commit messages for more details): - Fix stack overflow in the XKB text format parser when evaluating boolean negation. - Fix NULL-dereferences in the XKB text format parser when some unsupported tokens appear (the tokens are still parsed for backward compatibility). - Fix NULL-dereference in the XKB text format parser when parsing an xkb_geometry section. - Fix an infinite loop in the Compose text format parser on some inputs. - Fix an invalid free() when using multiple keysyms. - Replace the Unicode characters for the leftanglebracket and rightanglebracket keysyms from the deprecated LEFT/RIGHT-POINTING ANGLE BRACKET to MATHEMATICAL LEFT/RIGHT ANGLE BRACKET. - Reject out-of-range Unicode codepoints in xkb_keysym_to_utf8 and xkb_keysym_to_utf32. [Test case] install the update, check that nothing breaks wrt keyboard handling [Regression potential] slim, this has been in cosmic for some time already, and upstream specifically asked to backport this to stable releases [Impact] 0.8.2 has completed the fuzzing work started in 0.8.1, so backport the package from cosmic to fix these CVE's: CVE-2018-15853 CVE-2018-15854 CVE-2018-15855 CVE-2018-15856 CVE-2018-15857 CVE-2018-15858 CVE-2018-15859 CVE-2018-15861 CVE-2018-15862 CVE-2018-15863 CVE-2018-15864. upstream NEWS: libxkbcommon 0.8.2 - 2018-08-05 ================== - Fix various problems found with fuzzing (see commit messages for   more details):     - Fix a few NULL-dereferences, out-of-bounds access and undefined behavior       in the XKB text format parser. libxkbcommon 0.8.1 - 2018-08-03 ================== - Fix various problems found in the meson build (see commit messages for more   details):     - Fix compilation on Darwin.     - Fix compilation of the x11 tests and demos when XCB is installed in a       non-standard location.     - Fix xkbcommon-x11.pc missing the Requires specification. - Fix various problems found with fuzzing and Coverity (see commit messages for   more details):     - Fix stack overflow in the XKB text format parser when evaluating boolean       negation.     - Fix NULL-dereferences in the XKB text format parser when some unsupported       tokens appear (the tokens are still parsed for backward compatibility).     - Fix NULL-dereference in the XKB text format parser when parsing an       xkb_geometry section.     - Fix an infinite loop in the Compose text format parser on some inputs.     - Fix an invalid free() when using multiple keysyms. - Replace the Unicode characters for the leftanglebracket and rightanglebracket   keysyms from the deprecated LEFT/RIGHT-POINTING ANGLE BRACKET to   MATHEMATICAL LEFT/RIGHT ANGLE BRACKET. - Reject out-of-range Unicode codepoints in xkb_keysym_to_utf8 and   xkb_keysym_to_utf32. [Test case] install the update, check that nothing breaks wrt keyboard handling [Regression potential] slim, this has been in cosmic for some time already, and upstream specifically asked to backport this to stable releases There are some other changes to the packaging, but these are harmless and won't regress anything.
2018-10-04 12:12:34 Leonidas S. Barbosa cve linked 2018-15856
2018-11-08 09:27:00 Sebastien Bacher libxkbcommon (Ubuntu Bionic): status In Progress Fix Released
2018-11-08 10:12:29 Timo Aaltonen libxkbcommon (Ubuntu Bionic): status Fix Released Won't Fix