Updated xkbcomp packages fix security vulnerabilities
Publication date: 04 Dec 2025Modification date: 04 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2018-15853 , CVE-2018-15859 , CVE-2018-15861 , CVE-2018-15863
Description
Endless recursion in xkbcomp/expr.c resulting in a crash.
(CVE-2018-15853)
NULL pointer dereference when parsing invalid atoms in ExprResolveLhs
resulting in a crash. (CVE-2018-15859)
NULL pointer dereference in ExprResolveLhs resulting in a crash.
(CVE-2018-15861)
NULL pointer dereference in ResolveStateAndPredicate resulting in a
crash. (CVE-2018-15863)
References
- https://bugs.mageia.org/show_bug.cgi?id=34796
- https://www.openwall.com/lists/oss-security/2025/12/03/1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15853
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15859
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15861
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15863
SRPMS
9/core
- xkbcomp-1.4.6-1.1.mga9