Announcement

Collapse
No announcement yet.

X.Org Server & XWayland Hit By Four More Security Issues

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • X.Org Server & XWayland Hit By Four More Security Issues

    Phoronix: X.Org Server & XWayland Hit By Four More Security Issues

    Last year the X.Org Server disabled byte-swapped clients by default over being a large and known attack surface within the X.Org/XWayland codebase. That's proven itself to further be the case with 3 of 4 new CVEs made public today being around the byte-swapped code...

    Phoronix, Linux Hardware Reviews, Linux hardware benchmarks, Linux server benchmarks, Linux benchmarking, Desktop Linux, Linux performance, Open Source graphics, Linux How To, Ubuntu benchmarks, Ubuntu hardware, Phoronix Test Suite

  • #2
    Don't worry. I have heard from very reliable sources that Xorg is a finished project and does not need maintenance at all.

    Comment


    • #3
      Oh no, yet another X vs. Wayland fight incoming...
      Let's focus on the vulnerability.

      Comment


      • #4
        Originally posted by spicfoo View Post
        Don't worry. I have heard from very reliable sources that Xorg is a finished project and does not need maintenance at all.
        quite, not like anybody is using it, certainly not something like the vast majority of (sane) linux users. (And i'm not just saying that, i'm writing this from wayland, i'm just not sane, i thought I'd give it a solid try now that after almost 2 decades it was finally possible to get it mostly working on a normal PC, and all I have found are more reasons not to use wayland (ok I lied, I quite like waybar, there, 1 reason to use wayland, that's all i got, sry), i don't know why i'm still using it even, but I can tell you one thing, it isn't for security, for all that people say it's more secure, I have never seen a convincing explanation for why it would be more secure, except mayb theoretically against keyloggers but that particular feature is in return for breaking a shitload of usability and honestly isn't worth it, at least not as an 'always on' feature.)

        Comment


        • #5
          jeez, x on it's deathbed still has more security vulnerabilities than wayland has had in it's whole life.

          Comment


          • #6
            Originally posted by tildearrow View Post
            Oh no, yet another X vs. Wayland fight incoming...
            Someone needs to create an X vs Wayland rap battle video that will end the debate once and for all.

            Comment


            • #7
              Originally posted by spicfoo View Post
              Don't worry. I have heard from very reliable sources that Xorg is a finished project and does not need maintenance at all.
              Quite the opposite. The argument is that maintenance is all it should receive, and all feature development should be focused on Wayland. Obviously, as XWayland is going to be around for a little while for those dev teams too small or too lazy to upgrade to a newer toolkit, it is going to need maintenance to keep up and fix bugs.

              Whether or not I fully agree with that statement is entirely different. Not that it matters, because Linux desktops are moving to Wayland and unless the 3 X.org-only WMs that exist can maintain and develop X.org on their own, it's going to fall by the wayside no matter what anybody in the peanut gallery thinks.

              Comment


              • #8
                Even if there will be discovered 10, 100, 100 more security issues, I bet people will still use Linux Mint!
                And not only use it, but, they will even defend it!
                Anyway, people who care about their privacy and security used modern and Wayland-favoring desktop environments like KDE Plasma or Gnome and distros that support them properly.
                So congratulations to them.
                As for Linux Mint users and of other distros that don't support a modern desktop environments, they have made their bed.

                Comment


                • #9
                  I love that even in 2010 - almost 15 years ago at this point - people were poking fun at the age of Xorg

                  Comment


                  • #10
                    Originally posted by spicfoo View Post
                    Don't worry. I have heard from very reliable sources that Xorg is a finished project and does not need maintenance at all.
                    In fact, no one has even so much as peeked at the code for over 15 years since Wayland took the world by storm and 100% of users were immediately able to switch over full time. Or something like that.

                    Comment

                    Working...
                    X