package/x11r7/xlib_libXfont2: security bump to version 2.0.9

Fixes the following vulnerabilities:

- CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write
- CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer
  Overflow

For more details, see the advisory:
https://lists.x.org/archives/xorg-announce/2026-August/003734.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 21f18cd012)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
This commit is contained in:
Peter Korsgaard
2026-09-14 21:06:44 +02:00
committed by Raphaël Mélotte
parent 7c51110fc2
commit 0374d408e6
2 changed files with 4 additions and 4 deletions

View File

@@ -1,5 +1,5 @@
# From https://lists.x.org/archives/xorg-announce/2026-July/003715.html
sha256 f556c0e1093a4e6911cc90bc4b106d201902ee187fd74af206ff162f7e6a24d5 libXfont2-2.0.8.tar.xz
sha512 e14cc3fa03d7baa4554ee5754ab33f69ac1da3d509c686a5f705fde8cd07772be564d68cc18d9fd0beb5ed7b2f864fcd7f6bf4983f5c0db08a9c747d0e001531 libXfont2-2.0.8.tar.xz
# From https://lists.x.org/archives/xorg-announce/2026-August/003735.html
sha256 f042a370666815e7b941e9b7019024755bd1c6c2954afbfa515af378251799e2 libXfont2-2.0.9.tar.xz
sha512 ccd6d6abf6aa814a940d137813dba638f8259c3672abf00808d82df033c1026ae29d40c9068da4f112637338ad0d0fc15818a4afa9369a626c8f17e466b4fa72 libXfont2-2.0.9.tar.xz
# Locally calculated
sha256 3b1047f0d45584973866a40e3eedc74aea4c6ac636960d650ae05af603e6d1a8 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
XLIB_LIBXFONT2_VERSION = 2.0.8
XLIB_LIBXFONT2_VERSION = 2.0.9
XLIB_LIBXFONT2_SOURCE = libXfont2-$(XLIB_LIBXFONT2_VERSION).tar.xz
XLIB_LIBXFONT2_SITE = https://xorg.freedesktop.org/archive/individual/lib
XLIB_LIBXFONT2_LICENSE = MIT