CVE-2025-49175: Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors
A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.
Other sources
Out-of-Bounds Read vulnerability in the X Rendering extension's animated cursor handling. The server assumes at least one cursor is provided, but a client may pass none, causing an out-of-bounds read and server crash.
— Red Hat
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49175?
CVE-2025-49175 has been classified as a medium severity vulnerability due to its potential for causing application crashes.
How do I fix CVE-2025-49175?
To fix CVE-2025-49175, update to the latest version of X.Org X11 Server or TigerVNC which contains the security patch.
What are the consequences of CVE-2025-49175?
If exploited, CVE-2025-49175 can lead to an out-of-bounds read, resulting in a potential application crash.
Which software is affected by CVE-2025-49175?
CVE-2025-49175 affects X.Org X11 Server and TigerVNC implementations.
Is there a workaround for CVE-2025-49175?
Currently, no effective workaround is recommended other than applying the security updates provided by the software vendors.