CVE-2025-49176: Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension
A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
Other sources
nteger Overflow vulnerability in the Big Requests extension. The request length is multiplied before validation, allowing an overflow that defeats the size check, potentially leading to memory corruption.
— Red Hat
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49176?
CVE-2025-49176 has been classified as a medium severity vulnerability due to its potential for causing integer overflow.
How do I fix CVE-2025-49176?
To fix CVE-2025-49176, update to the latest version of the affected software that addresses this vulnerability.
What software is affected by CVE-2025-49176?
CVE-2025-49176 affects the X.Org X11 Server and TigerVNC products.
What type of vulnerability is CVE-2025-49176?
CVE-2025-49176 is an integer overflow vulnerability related to request size checks in the Big Requests extension.
What can happen if CVE-2025-49176 is exploited?
If exploited, CVE-2025-49176 may lead to denial of service or potentially allow attackers to bypass size limitations.