mbox series

[meta-oe,scarthgap,0/5] TigerVNC CVEs - alternative version

Message ID 20260201140421.768419-1-skandigraun@gmail.com
Headers show
Series TigerVNC CVEs - alternative version | expand

Message

Gyorgy Sarvari Feb. 1, 2026, 2:04 p.m. UTC
This is an alernative fix for a previous series[1] fixing the outstanding CVEs
for TigerVNC. This series brings the xserver component in sync with oe-core,
now they use the same version.

xserver 21 support however was only added to TigerVNC two versions later, in
verison 1.13. The first commit contains patches to support this verison of
xserver. I was able to compile and connect to a VNC session successfully
from core-image-sato using these patches.

The rest of the cherry-picks just ignore the CVEs that are fixed in this
version of xserver.

[1]: https://lists.openembedded.org/g/openembedded-devel/message/123940

---

Gyorgy Sarvari (5):
  tigervnc: sync xserver component with oe-core
  tigervnc: ignore CVE-2014-8241
  tigervnc: ignore CVE-2023-6377
  tigervnc: ignore CVE-2023-6478
  tigervnc: ignore CVE-2025-26594...26601

 ...ncrease-supported-Xorg-version-to-1..patch | 29 ++++++
 ...server21.1.1.patch-Add-Xorg-21-patch.patch | 95 +++++++++++++++++++
 .../files/0001-xvnc-adapt-for-1.21.patch      | 46 +++++++++
 .../tigervnc/tigervnc_1.11.0.bb               | 45 +++++----
 4 files changed, 192 insertions(+), 23 deletions(-)
 create mode 100644 meta-oe/recipes-graphics/tigervnc/files/0001-xorg-version.h-Increase-supported-Xorg-version-to-1..patch
 create mode 100644 meta-oe/recipes-graphics/tigervnc/files/0001-xserver21.1.1.patch-Add-Xorg-21-patch.patch
 create mode 100644 meta-oe/recipes-graphics/tigervnc/files/0001-xvnc-adapt-for-1.21.patch