Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-49178

Опубликовано: 17 июн. 2025
Источник: redhat
CVSS3: 5.5

Описание

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

Отчет

This vulnerability is rated as a moderate severity because the flaw exists in the X server’s request handling logic, where the “bytes to ignore” field in a client request is not properly validated. A malicious client can submit a request specifying a non-zero 'bytes to ignore' value that exceeds the actual request size, causing the server to advance its internal input pointer incorrectly. As a result, the server may skip over pending requests from other clients, disrupting normal processing and effectively denying service to legitimate users. This vulnerability primarily impacts system availability

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverWill not fix
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2025:930423.06.2025
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2025:1037707.07.2025
Red Hat Enterprise Linux 7.7 Advanced Update SupporttigervncFixedRHSA-2025:1037607.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2025:1036007.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2025:1037507.07.2025
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8tigervncFixedRHSA-2025:939223.06.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupporttigervncFixedRHSA-2025:1037807.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-667
https://bugzilla.redhat.com/show_bug.cgi?id=2369977xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Unprocessed Client Request Due to Bytes to Ignore

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
5 месяцев назад

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

CVSS3: 5.5
nvd
5 месяцев назад

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

CVSS3: 5.5
msrc
3 месяца назад

Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: unprocessed client request due to bytes to ignore

CVSS3: 5.5
debian
5 месяцев назад

A flaw was found in the X server's request handling. Non-zero 'bytes t ...

CVSS3: 5.5
github
5 месяцев назад

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

5.5 Medium

CVSS3