Описание
Security update for xorg-x11-server
This update for xorg-x11-server fixes the following issues:
- CVE-2025-49176: Fixed the integer overflow in Big Requests Extension (bsc#1244084).
Список пакетов
SUSE Enterprise Storage 7.1
xorg-x11-server-1.20.3-150200.22.5.108.1
xorg-x11-server-extra-1.20.3-150200.22.5.108.1
xorg-x11-server-sdk-1.20.3-150200.22.5.108.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
xorg-x11-server-1.20.3-150200.22.5.108.1
xorg-x11-server-extra-1.20.3-150200.22.5.108.1
xorg-x11-server-sdk-1.20.3-150200.22.5.108.1
SUSE Linux Enterprise Server 15 SP3-LTSS
xorg-x11-server-1.20.3-150200.22.5.108.1
xorg-x11-server-extra-1.20.3-150200.22.5.108.1
xorg-x11-server-sdk-1.20.3-150200.22.5.108.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
xorg-x11-server-1.20.3-150200.22.5.108.1
xorg-x11-server-extra-1.20.3-150200.22.5.108.1
xorg-x11-server-sdk-1.20.3-150200.22.5.108.1
SUSE Linux Enterprise Workstation Extension 15 SP6
xorg-x11-server-wayland-1.20.3-150200.22.5.108.1
SUSE Linux Enterprise Workstation Extension 15 SP7
xorg-x11-server-wayland-1.20.3-150200.22.5.108.1
Ссылки
- Link for SUSE-SU-2025:02208-1
- E-Mail link for SUSE-SU-2025:02208-1
- SUSE Security Ratings
- SUSE Bug 1244084
- SUSE CVE CVE-2025-49176 page
Описание
A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
Затронутые продукты
SUSE Enterprise Storage 7.1:xorg-x11-server-1.20.3-150200.22.5.108.1
SUSE Enterprise Storage 7.1:xorg-x11-server-extra-1.20.3-150200.22.5.108.1
SUSE Enterprise Storage 7.1:xorg-x11-server-sdk-1.20.3-150200.22.5.108.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:xorg-x11-server-1.20.3-150200.22.5.108.1
Ссылки
- CVE-2025-49176
- SUSE Bug 1244084