CVE-2025-49179: Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension
A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.
Other sources
Integer Overflow vulnerability in the X Record extension. Lack of proper checks in RecordSanityCheckRegisterClients allows clients to send large values causing integer overflows, potentially leading to memory corruption.
— Red Hat
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49179?
CVE-2025-49179 is considered a medium severity vulnerability due to the potential for bypassing length checks.
How do I fix CVE-2025-49179?
To fix CVE-2025-49179, it is recommended to update the Xorg X11 Server and TigerVNC to their latest patched versions.
What are the potential impacts of CVE-2025-49179?
The impacts of CVE-2025-49179 may include unauthorized access or manipulation of data by exploiting integer overflow in the X Record extension.
Is CVE-2025-49179 specific to any versions of software?
CVE-2025-49179 affects the Xorg X11 Server and TigerVNC, but specific versions were not stated in the vulnerability description.
Who is affected by CVE-2025-49179?
Any users or systems utilizing the Xorg X11 Server or TigerVNC are potentially affected by CVE-2025-49179.