ALAS2023-2025-939


Amazon Linux 2023 Security Advisory: ALAS2023-2025-939
Advisory Released Date: 2025-04-14
Advisory Updated Date: 2025-04-14
Severity: Medium

Issue Overview:

In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock. (CVE-2022-49737)


Affected Packages:

xorg-x11-server


Issue Correction:
Run dnf update xorg-x11-server --releasever 2023.7.20250414 to update your system.

New Packages:
aarch64:
    xorg-x11-server-Xorg-debuginfo-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-Xephyr-debuginfo-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-Xvfb-debuginfo-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-devel-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-common-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-Xnest-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-Xorg-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-Xvfb-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-Xnest-debuginfo-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-debuginfo-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-Xephyr-21.1.13-5.amzn2023.0.5.aarch64
    xorg-x11-server-debugsource-21.1.13-5.amzn2023.0.5.aarch64

noarch:
    xorg-x11-server-source-21.1.13-5.amzn2023.0.5.noarch

src:
    xorg-x11-server-21.1.13-5.amzn2023.0.5.src

x86_64:
    xorg-x11-server-Xnest-debuginfo-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-Xorg-debuginfo-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-debuginfo-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-Xephyr-debuginfo-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-Xorg-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-devel-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-Xnest-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-Xvfb-debuginfo-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-common-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-Xvfb-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-Xephyr-21.1.13-5.amzn2023.0.5.x86_64
    xorg-x11-server-debugsource-21.1.13-5.amzn2023.0.5.x86_64