Skip to content

(release/25.2) glx: fix DrawableGone use-after-free without rejecting duplicate drawables - #3333

Open
metux wants to merge 1 commit into
release/25.2from
pr/release/25.2-glx-fix-drawablegone-use-after-free-without-rejecting-duplicate-drawables_2026-07-21_13-35-16
Open

(release/25.2) glx: fix DrawableGone use-after-free without rejecting duplicate drawables#3333
metux wants to merge 1 commit into
release/25.2from
pr/release/25.2-glx-fix-drawablegone-use-after-free-without-rejecting-duplicate-drawables_2026-07-21_13-35-16

Conversation

@metux

@metux metux commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

A window can have more than one __GLXdrawable registered under its X id.
On teardown DrawableGone() freed the partner with FreeResourceByType(),
which matches only id+type and so frees an arbitrary one, leaving the
survivor dangling -> later use-after-free (issue #1491).

Add FreeResourceByTypeValue() (internal, dix/resource_priv.h) that also
matches the value, and use it in DrawableGone() to free the entry for
this exact drawable. Fixes the UAF while keeping duplicate glXCreateWindow
working, unlike the previous fix that rejected it and broke clients.

Assisted-by: Claude Opus 4.8 noreply@anthropic.com
Signed-off-by: Kiyoshi Spreclerg kiyoshi_pip@protonmail.com
(cherry picked from commit 36b8a33)

Backport of #3329 (master). Cherry-picked from commit 36b8a33.

…ables

A window can have more than one __GLXdrawable registered under its X id.
On teardown DrawableGone() freed the partner with FreeResourceByType(),
which matches only id+type and so frees an arbitrary one, leaving the
survivor dangling -> later use-after-free (issue #1491).

Add FreeResourceByTypeValue() (internal, dix/resource_priv.h) that also
matches the value, and use it in DrawableGone() to free the entry for
this exact drawable. Fixes the UAF while keeping duplicate glXCreateWindow
working, unlike the previous fix that rejected it and broke clients.

Assisted-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Kiyoshi Spreclerg <kiyoshi_pip@protonmail.com>
(cherry picked from commit 36b8a33)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants