xserver/composite
Olivier Fourdan 26ef545b35 composite: Fix use-after-free of the COW
ZDI-CAN-19866/CVE-2023-1393

If a client explicitly destroys the compositor overlay window (aka COW),
we would leave a dangling pointer to that window in the CompScreen
structure, which will trigger a use-after-free later.

Make sure to clear the CompScreen pointer to the COW when the latter gets
destroyed explicitly by the client.

This vulnerability was discovered by:
Jan-Niklas Sohn working with Trend Micro Zero Day Initiative

Signed-off-by: Olivier Fourdan <ofourdan@redhat.com>
Reviewed-by: Adam Jackson <ajax@redhat.com>
2023-03-29 13:34:11 +02:00
..
compalloc.c Remove "All rights reserved" from Oracle copyright notices 2023-02-25 09:40:41 -08:00
compext.c Remove "All rights reserved" from Oracle copyright notices 2023-02-25 09:40:41 -08:00
compinit.c Remove "All rights reserved" from Oracle copyright notices 2023-02-25 09:40:41 -08:00
compint.h Remove "All rights reserved" from Oracle copyright notices 2023-02-25 09:40:41 -08:00
compositeext.h composite: Export compIsAlternateVisual 2017-01-25 11:27:06 -05:00
compoverlay.c Remove "All rights reserved" from Oracle copyright notices 2023-02-25 09:40:41 -08:00
compwindow.c composite: Fix use-after-free of the COW 2023-03-29 13:34:11 +02:00
meson.build meson: hide C API if Xorg is disabled (like autotools) 2021-03-11 00:22:36 +00:00