CVE-2025-49179

A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.
References
Link Resource
https://access.redhat.com/errata/RHSA-2025:10258
https://access.redhat.com/errata/RHSA-2025:10342
https://access.redhat.com/errata/RHSA-2025:10343
https://access.redhat.com/errata/RHSA-2025:10344
https://access.redhat.com/errata/RHSA-2025:10346
https://access.redhat.com/errata/RHSA-2025:10347
https://access.redhat.com/errata/RHSA-2025:10348
https://access.redhat.com/errata/RHSA-2025:10349
https://access.redhat.com/errata/RHSA-2025:10350
https://access.redhat.com/errata/RHSA-2025:10351
https://access.redhat.com/errata/RHSA-2025:10352
https://access.redhat.com/errata/RHSA-2025:10355
https://access.redhat.com/errata/RHSA-2025:10356
https://access.redhat.com/errata/RHSA-2025:10360
https://access.redhat.com/errata/RHSA-2025:10370
https://access.redhat.com/errata/RHSA-2025:10374
https://access.redhat.com/errata/RHSA-2025:10375
https://access.redhat.com/errata/RHSA-2025:10376
https://access.redhat.com/errata/RHSA-2025:10377
https://access.redhat.com/errata/RHSA-2025:10378
https://access.redhat.com/errata/RHSA-2025:10381
https://access.redhat.com/errata/RHSA-2025:10410
https://access.redhat.com/errata/RHSA-2025:9303
https://access.redhat.com/errata/RHSA-2025:9304
https://access.redhat.com/errata/RHSA-2025:9305
https://access.redhat.com/errata/RHSA-2025:9306
https://access.redhat.com/errata/RHSA-2025:9392
https://access.redhat.com/errata/RHSA-2025:9964
https://access.redhat.com/security/cve/CVE-2025-49179
https://bugzilla.redhat.com/show_bug.cgi?id=2369978
https://gitlab.freedesktop.org/xorg/xserver/-/commit/2bde9ca49a8fd9a1e6697d5e7ef837870d66f5d4
https://www.x.org/wiki/Development/Security/
https://lists.debian.org/debian-lts-announce/2025/06/msg00028.html
Configurations

No configuration.

History

11 Dec 2025, 16:16

Type Values Removed Values Added
References
  • () https://www.x.org/wiki/Development/Security/ -

09 Dec 2025, 23:15

Type Values Removed Values Added
References
  • () https://gitlab.freedesktop.org/xorg/xserver/-/commit/2bde9ca49a8fd9a1e6697d5e7ef837870d66f5d4 -

03 Nov 2025, 20:19

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/06/msg00028.html -

07 Jul 2025, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:10381 -
  • () https://access.redhat.com/errata/RHSA-2025:10410 -

07 Jul 2025, 08:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:10344 -
  • () https://access.redhat.com/errata/RHSA-2025:10346 -
  • () https://access.redhat.com/errata/RHSA-2025:10349 -
  • () https://access.redhat.com/errata/RHSA-2025:10350 -
  • () https://access.redhat.com/errata/RHSA-2025:10351 -
  • () https://access.redhat.com/errata/RHSA-2025:10352 -
  • () https://access.redhat.com/errata/RHSA-2025:10355 -
  • () https://access.redhat.com/errata/RHSA-2025:10356 -
  • () https://access.redhat.com/errata/RHSA-2025:10360 -
  • () https://access.redhat.com/errata/RHSA-2025:10370 -
  • () https://access.redhat.com/errata/RHSA-2025:10374 -
  • () https://access.redhat.com/errata/RHSA-2025:10375 -
  • () https://access.redhat.com/errata/RHSA-2025:10376 -
  • () https://access.redhat.com/errata/RHSA-2025:10377 -
  • () https://access.redhat.com/errata/RHSA-2025:10378 -

07 Jul 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:10342 -
  • () https://access.redhat.com/errata/RHSA-2025:10343 -
  • () https://access.redhat.com/errata/RHSA-2025:10347 -
  • () https://access.redhat.com/errata/RHSA-2025:10348 -

02 Jul 2025, 20:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:10258 -

30 Jun 2025, 20:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9964 -

30 Jun 2025, 09:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.6
v2 : unknown
v3 : 7.3

23 Jun 2025, 19:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9303 -
  • () https://access.redhat.com/errata/RHSA-2025:9304 -
  • () https://access.redhat.com/errata/RHSA-2025:9305 -
  • () https://access.redhat.com/errata/RHSA-2025:9306 -
  • () https://access.redhat.com/errata/RHSA-2025:9392 -

23 Jun 2025, 07:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9303 -
  • () https://access.redhat.com/errata/RHSA-2025:9304 -
  • () https://access.redhat.com/errata/RHSA-2025:9305 -
  • () https://access.redhat.com/errata/RHSA-2025:9306 -
References
  • () https://access.redhat.com/errata/RHSA-2025:9303 -
  • () https://access.redhat.com/errata/RHSA-2025:9304 -
  • () https://access.redhat.com/errata/RHSA-2025:9305 -
  • () https://access.redhat.com/errata/RHSA-2025:9306 -
References
  • () https://access.redhat.com/errata/RHSA-2025:9303 -
  • () https://access.redhat.com/errata/RHSA-2025:9304 -
  • () https://access.redhat.com/errata/RHSA-2025:9305 -
  • () https://access.redhat.com/errata/RHSA-2025:9306 -
Summary
  • (es) Se encontró una falla en la extensión X Record. La función RecordSanityCheckRegisterClients no verifica si hay un desbordamiento de enteros al calcular la longitud de la solicitud, lo que permite que un cliente omita las verificaciones de longitud.

17 Jun 2025, 20:50

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9303', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9304', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9305', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9306', 'source': 'secalert@redhat.com'}
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9303', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9304', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9305', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9306', 'source': 'secalert@redhat.com'}
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9303', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9304', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9305', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9306', 'source': 'secalert@redhat.com'}

17 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 15:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-49179

Mitre link : CVE-2025-49179

CVE.ORG link : CVE-2025-49179


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound