CVE-2025-49180: Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extension
A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocate.
Other sources
Integer Overflow vulnerability in the RandR extension's RRChangeProviderProperty function. Improper validation allows clients to cause integer overflows during memory allocation calculations, potentially leading to memory corruption.
— Red Hat
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extension
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49180?
CVE-2025-49180 is classified as a high severity vulnerability due to the potential for an integer overflow leading to memory allocation issues.
How do I fix CVE-2025-49180?
To address CVE-2025-49180, ensure that you apply the latest patches or updates provided for the affected software, such as X.Org Xorg and TigerVNC.
Which software is affected by CVE-2025-49180?
CVE-2025-49180 affects X.Org Xorg, X.Org X11 Server, and TigerVNC software.
What is the impact of CVE-2025-49180?
The impact of CVE-2025-49180 may include potential application crashes or exploitation through memory corruption due to improper input validation.
When was CVE-2025-49180 disclosed?
CVE-2025-49180 was disclosed in 2025, highlighting a vulnerability in the RandR extension related to the RRChangeProviderProperty function.