Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-49175

Опубликовано: 17 июн. 2025
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.

Отчет

This vulnerability is rated as an important severity because the flaw exists in the X Rendering extension of the X.Org X server, specifically in the handling of animated cursors, when a client request provides zero cursors, the server erroneously assumes that at least one cursor is present and proceeds to access elements in the non-existent array. This logic error causes an out-of-bounds read, which can lead to a server crash and denial of service, the flaw could expose limited uninitialized memory, potentially resulting in minor information disclosure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverWill not fix
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2025:930423.06.2025
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2025:1037707.07.2025
Red Hat Enterprise Linux 7.7 Advanced Update SupporttigervncFixedRHSA-2025:1037607.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2025:1036007.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2025:1037507.07.2025
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8tigervncFixedRHSA-2025:939223.06.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupporttigervncFixedRHSA-2025:1037807.07.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2369947xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Out-of-Bounds Read in X Rendering Extension Animated Cursors

EPSS

Процентиль: 6%
0.00027
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 2 месяцев назад

A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.

CVSS3: 6.1
nvd
около 2 месяцев назад

A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.

CVSS3: 6.1
debian
около 2 месяцев назад

A flaw was found in the X Rendering extension's handling of animated c ...

CVSS3: 5.5
github
около 2 месяцев назад

A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.

suse-cvrf
около 2 месяцев назад

Security update for xorg-x11-server

EPSS

Процентиль: 6%
0.00027
Низкий

6.1 Medium

CVSS3