News: 0001596510

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

X.Org Server's xkbcomp Updated For Four Security Issues Dating Back Years

([X.Org] 11 Minutes Ago xkbcomp 1.5)


Red Hat's Peter Hutterer announced the release today of xkbcomp 1.5, the CLI utility used for compiling X Keyboard Extension (XBD) keyboard descriptions for the X.Org Server. Driving this new xkbcomp release are fixes for four security issues.

These four security issues originate from within code originally inside the libxkbcommon library and back in 2018 was flagged with four CVEs. Those security issues included endless recursion resulting in a crash and three null pointer dereference issues leading to possible crashes.

Those 2018 security patches to libxkbcommon are now applied to the xkbcomp codebase for addressing those C issues. More details for those interested in today's X.Org Security Advisory resulting in the xkbcomp 1.5 release can be found via the [1]Xorg-announce mailing list .

Besides these four 2018 CVE fixes, [2]xkbcomp 1.5 also has added support for the Meson build system and other minor fixes collected over the past two years or so since the prior 1.4 point release.



[1] https://lists.x.org/archives/xorg-announce/2025-December/003644.html

[2] https://lists.x.org/archives/xorg-announce/2025-December/003645.html



Correspondence Corollary:
An experiment may be considered a success if no more than half
your data must be discarded to obtain correspondence with your theory.