#21736 closed enhancement (fixed)

xorg-server-21.1.17

Reported by: zeckma Owned by: zeckma
Priority: elevated Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New patch release. This release fixes 6 security vulnerabilities.

  • CVE-2025-49175: This vulnerability introduced in X11R6.7 allows for a client to provide no cursor to the Xserver which causes an out of bounds read and crashes the server via the X Rendering Extension.
  • CVE-2025-49176: This vulnerability introduced in X11R6.0 allows for integer overflow before testing for said overflow in the Big Requests Extension.
  • CVE-2025-49177: This vulnerability introduced in Xorg-Server-21.0.99.1/Xwayland-22.0.99.1 allows for a client sending shorter requests and thus read old data via the XFIXES Extension 6.
  • CVE-2025-49178: This vulnerability introduced in Xorg-1.10.0 allows for an input buffer to be shared between clients, causing one of the clients to hang due to bytes being ignored may be non-zero despite having a full request.
  • CVE-2025-49179: This vulnerability introduced in X11R6.1 allows for an integer overflow in the X Record Extension.
  • CVE-2025-49180: This vulnerability introduced in Xorg-Server-1.12.99.901 allows for an integer overflow in the RandR Extension.

These vulnerabilities are shared with Xwayland and all of them are rated MEDIUM.

Change History (2)

comment:1 by zeckma, 16 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by zeckma, 16 months ago

Resolution: → fixed
Status: assigned → closed
Note: See TracTickets for help on using tickets.