X.org Security Advisory: multiple security issues X.Org X server and Xwayland

birdculture | 204 points

Wonder how these play out against the https://github.com/X11Libre/xserver base, would be interesting to hear from that end as to how these things are handled. My understanding is that they address any sec issues that arise on x.org but it would be fascinating if the issues are already mitigated since XLibre updated their xserver port with 1000s of issues that were never addressed on the x.org side of things.

dingdingdang | 2 days ago

Good that people are finding and fixing these, but basically allowing any untrusted client to talk to your X server is asking for trouble just by design. (Bonus points if you have any Tcl/Tk apps running, where you can simply transmit commands for the program to run via the X server.)

rwmj | 3 days ago

Coverity is pretty good about finding these kinds of bugs. Is there a reason why a project as significant as Xorg isn't taking advantage of their gratis access for that tool?

kevin_thibedeau | 2 days ago

The main pain in linux is graphics. It's a shame.

ekvintroj | 2 days ago

Don't kill xorg! :(

shevy-java | 2 days ago

Would Fil-C have prevented the first or third?

samtheprogram | 2 days ago

Considering how nicely Weston with SW rendering runs in Fil-C, I bet that the X server will run fine in Fil-C, too.

Fil-C exhibits the lowest overhead in code that spends its time on primitive bits.

Fil-C exhibits the highest overhead in code that chases pointers.

I'm assuming X is the former. Weston seems to be.

pizlonator | 2 days ago

How did Twitter get away with taking X.com?

If it was the other way around, would an open source or whatever project have been able to take Twitter.org?

Razengan | 2 days ago

_Roughtly_ speaking, X11 is only there for old games and the steam client. It is even worse with the steam client since the main executable in still 32bits.

sylware | 2 days ago

[dead]

TacticalCoder | 2 days ago