Peter Hutterer
564ccf2ce9
mi: reset the PointerWindows reference on screen switch
...
PointerWindows[] keeps a reference to the last window our sprite
entered - changes are usually handled by CheckMotion().
If we switch between screens via XWarpPointer our
dev->spriteInfo->sprite->win is set to the new screen's root window.
If there's another window at the cursor location CheckMotion() will
trigger the right enter/leave events later. If there is not, it skips
that process and we never trigger LeaveWindow() - PointerWindows[] for
the device still refers to the previous window.
If that window is destroyed we have a dangling reference that will
eventually cause a use-after-free bug when checking the window hierarchy
later.
To trigger this, we require:
- two protocol screens
- XWarpPointer to the other screen's root window
- XDestroyWindow before entering any other window
This is a niche bug so we hack around it by making sure we reset the
PointerWindows[] entry so we cannot have a dangling pointer. This
doesn't handle Enter/Leave events correctly but the previous code didn't
either.
CVE-2023-5380, ZDI-CAN-21608
This vulnerability was discovered by:
Sri working with Trend Micro Zero Day Initiative
Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
Reviewed-by: Adam Jackson <ajax@redhat.com>
2023-10-25 00:37:47 +00:00
..
meson.build
meson: hide C API if Xorg is disabled (like autotools)
2021-03-11 00:22:36 +00:00
mi.h
mi: Add a callback to notify driver about input event submission
2020-09-24 17:33:22 +00:00
miarc.c
mi: Use memcpy() instead of memmove() when buffers are known not to overlap
2022-08-29 21:10:51 +00:00
mibitblt.c
Revert "mi: Shortcut miDoCopy/miCopyArea based on clipList"
2021-01-29 13:51:06 +00:00
micmap.c
Remove "All rights reserved" from Oracle copyright notices
2023-02-25 09:40:41 -08:00
micmap.h
Introduce a consistent coding style
2012-03-21 13:54:42 -07:00
micoord.h
mi: Remove semi-arbitrary arch awareness in packed coordinate macros
2014-07-28 12:20:44 -07:00
micopy.c
Revert "mi: Shortcut miDoCopy/miCopyArea based on clipList"
2021-01-29 13:51:06 +00:00
midash.c
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
midispcur.c
cursor: drop ARGB_CURSOR
2015-06-30 12:17:51 +10:00
mieq.c
Implement gesture processing logic
2021-05-30 13:26:42 +03:00
miexpose.c
mi: Fix up alpha channel if needed in miPaintWindow
2023-07-20 10:14:56 +02:00
mifillarc.c
mi: Partial pie-slice filled arcs may need more space for spans
2015-04-13 18:41:26 -07:00
mifillarc.h
mi: Unexport arc fill implementation details
2014-10-27 15:45:21 -04:00
mifillrct.c
Convert mi & miext to new *allocarray functions
2015-04-21 16:58:08 -07:00
mifpoly.h
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
migc.c
fb: Remove 24bpp support (v3)
2017-03-17 15:14:42 -04:00
migc.h
mi: Add include guards to migc.h
2017-02-16 15:10:32 -05:00
miglblt.c
Fix spelling/wording issues
2020-07-05 13:07:33 -07:00
miinitext.c
Allow disabling the SHAPE extension at runtime
2023-03-03 18:28:40 +00:00
miinitext.h
mi: List extensions in usage message
2021-01-29 12:52:09 +00:00
miline.h
Introduce a consistent coding style
2012-03-21 13:54:42 -07:00
mioverlay.c
mioverlay.c: remove shadowed pScreen.
2015-08-17 18:23:40 -07:00
mioverlay.h
Introduce a consistent coding style
2012-03-21 13:54:42 -07:00
mipointer.c
mi: reset the PointerWindows reference on screen switch
2023-10-25 00:37:47 +00:00
mipointer.h
Fix spelling/wording issues
2020-07-05 13:07:33 -07:00
mipointrst.h
dix: Update some comments to reflect the new non-SIGIO input model
2016-06-08 11:36:32 -04:00
mipoly.c
Convert mi & miext to new *allocarray functions
2015-04-21 16:58:08 -07:00
mipoly.h
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
mipolypnt.c
Convert mi & miext to new *allocarray functions
2015-04-21 16:58:08 -07:00
mipolyrect.c
Convert mi & miext to new *allocarray functions
2015-04-21 16:58:08 -07:00
mipolyseg.c
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
mipolytext.c
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
mipushpxl.c
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
miscanfill.h
Introduce a consistent coding style
2012-03-21 13:54:42 -07:00
miscrinit.c
Fix spelling/wording issues
2020-07-05 13:07:33 -07:00
misprite.c
misprite: Stop wrapping GetImage/GetSpans
2019-10-30 16:26:01 +00:00
misprite.h
Introduce a consistent coding style
2012-03-21 13:54:42 -07:00
mistruct.h
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
mivalidate.h
Introduce a consistent coding style
2012-03-21 13:54:42 -07:00
mivaltree.c
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
miwideline.c
mi: Always initialize edge1 and edge2 in miLineArc
2015-08-17 18:50:25 -07:00
miwideline.h
mi: Fold mispans.c into miwideline.c
2014-10-27 15:45:22 -04:00
miwindow.c
dix: Restore PaintWindow screen hook
2015-07-08 16:41:28 -04:00
mizerarc.c
Convert mi & miext to new *allocarray functions
2015-04-21 16:58:08 -07:00
mizerarc.h
Introduce a consistent coding style
2012-03-21 13:54:42 -07:00
mizerclip.c
Drop trailing whitespaces
2014-11-12 10:25:00 +10:00
mizerline.c
Fix spelling/wording issues
2020-07-05 13:07:33 -07:00