Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-49176

Опубликовано: 17 июн. 2025
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.

Отчет

This vulnerability is rated as an important severity because this flaw exists in the Big Requests extension of the X.Org X server, where the length of client requests is multiplied by 4 before validating against the maximum allowed size. This computation can cause an integer overflow when a sufficiently large length value is provided, resulting in a wrapped-around total length that appears valid to the size check logic, leading to out-of-bounds memory access, successful exploitation can cause denial of service by crashing the server and may permit memory corruption, compromising system integrity and availability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverWill not fix
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2025:930423.06.2025
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2025:1037707.07.2025
Red Hat Enterprise Linux 7.7 Advanced Update SupporttigervncFixedRHSA-2025:1037607.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2025:1036007.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2025:1037507.07.2025
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8tigervncFixedRHSA-2025:939223.06.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupporttigervncFixedRHSA-2025:1037807.07.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2369954xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer Overflow in Big Requests Extension

EPSS

Процентиль: 6%
0.00027
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 2 месяцев назад

A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.

CVSS3: 7.3
nvd
около 2 месяцев назад

A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.

CVSS3: 7.3
debian
около 2 месяцев назад

A flaw was found in the Big Requests extension. The request length is ...

suse-cvrf
около 1 месяца назад

Security update for xorg-x11-server

suse-cvrf
около 1 месяца назад

Security update for xorg-x11-server

EPSS

Процентиль: 6%
0.00027
Низкий

7.3 High

CVSS3

Уязвимость CVE-2025-49176