Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-49178

Опубликовано: 17 июн. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

Отчет

This vulnerability is rated as a moderate severity because the flaw exists in the X server’s request handling logic, where the “bytes to ignore” field in a client request is not properly validated. A malicious client can submit a request specifying a non-zero 'bytes to ignore' value that exceeds the actual request size, causing the server to advance its internal input pointer incorrectly. As a result, the server may skip over pending requests from other clients, disrupting normal processing and effectively denying service to legitimate users. This vulnerability primarily impacts system availability

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverWill not fix
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2025:930423.06.2025
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2025:1037707.07.2025
Red Hat Enterprise Linux 7.7 Advanced Update SupporttigervncFixedRHSA-2025:1037607.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2025:1036007.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2025:1037507.07.2025
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8tigervncFixedRHSA-2025:939223.06.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupporttigervncFixedRHSA-2025:1037807.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-667
https://bugzilla.redhat.com/show_bug.cgi?id=2369977xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Unprocessed Client Request Due to Bytes to Ignore

EPSS

Процентиль: 5%
0.00025
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

CVSS3: 5.5
nvd
около 2 месяцев назад

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

CVSS3: 5.5
debian
около 2 месяцев назад

A flaw was found in the X server's request handling. Non-zero 'bytes t ...

CVSS3: 5.5
github
около 2 месяцев назад

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

suse-cvrf
около 2 месяцев назад

Security update for xorg-x11-server

EPSS

Процентиль: 5%
0.00025
Низкий

5.5 Medium

CVSS3