﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
21736	xorg-server-21.1.17	zeckma	zeckma	"New patch release. This release fixes 6 security vulnerabilities.

- CVE-2025-49175: This vulnerability introduced in X11R6.7 allows for a client to provide no cursor to the Xserver which causes an out of bounds read and crashes the server via the X Rendering Extension.
- CVE-2025-49176: This vulnerability introduced in X11R6.0 allows for integer overflow before testing for said overflow in the Big Requests Extension.
- CVE-2025-49177: This vulnerability introduced in Xorg-Server-21.0.99.1/Xwayland-22.0.99.1 allows for a client sending shorter requests and thus read old data via the XFIXES Extension 6.
- CVE-2025-49178: This vulnerability introduced in Xorg-1.10.0 allows for an input buffer to be shared between clients, causing one of the clients to hang due to bytes being ignored may be non-zero despite having a full request.
- CVE-2025-49179: This vulnerability introduced in X11R6.1 allows for an integer overflow in the X Record Extension.
- CVE-2025-49180: This vulnerability introduced in Xorg-Server-1.12.99.901 allows for an integer overflow in the RandR Extension.

These vulnerabilities are shared with Xwayland and all of them are rated MEDIUM."	enhancement	closed	elevated	12.4	BOOK	git	medium	fixed		
