Bug 2369954 (CVE-2025-49176) - CVE-2025-49176 xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer Overflow in Big Requests Extension
Summary: CVE-2025-49176 xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer O...
Keywords:
Status: NEW
Alias: CVE-2025-49176
Deadline: 2025-06-17
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2375554 2375555 2375556
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-06-03 07:20 UTC by OSIDB Bzimport
Modified: 2025-07-07 12:23 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:10258 0 None None None 2025-07-02 16:28:15 UTC
Red Hat Product Errata RHSA-2025:10342 0 None None None 2025-07-07 01:22:37 UTC
Red Hat Product Errata RHSA-2025:10343 0 None None None 2025-07-07 01:31:19 UTC
Red Hat Product Errata RHSA-2025:10344 0 None None None 2025-07-07 02:22:29 UTC
Red Hat Product Errata RHSA-2025:10346 0 None None None 2025-07-07 01:58:15 UTC
Red Hat Product Errata RHSA-2025:10347 0 None None None 2025-07-07 01:23:12 UTC
Red Hat Product Errata RHSA-2025:10348 0 None None None 2025-07-07 01:21:56 UTC
Red Hat Product Errata RHSA-2025:10349 0 None None None 2025-07-07 02:33:43 UTC
Red Hat Product Errata RHSA-2025:10350 0 None None None 2025-07-07 02:37:18 UTC
Red Hat Product Errata RHSA-2025:10351 0 None None None 2025-07-07 02:41:07 UTC
Red Hat Product Errata RHSA-2025:10352 0 None None None 2025-07-07 02:33:02 UTC
Red Hat Product Errata RHSA-2025:10355 0 None None None 2025-07-07 02:42:46 UTC
Red Hat Product Errata RHSA-2025:10356 0 None None None 2025-07-07 02:45:04 UTC
Red Hat Product Errata RHSA-2025:10360 0 None None None 2025-07-07 02:32:44 UTC
Red Hat Product Errata RHSA-2025:10370 0 None None None 2025-07-07 05:29:49 UTC
Red Hat Product Errata RHSA-2025:10374 0 None None None 2025-07-07 07:22:01 UTC
Red Hat Product Errata RHSA-2025:10375 0 None None None 2025-07-07 07:21:41 UTC
Red Hat Product Errata RHSA-2025:10376 0 None None None 2025-07-07 07:18:14 UTC
Red Hat Product Errata RHSA-2025:10377 0 None None None 2025-07-07 07:24:53 UTC
Red Hat Product Errata RHSA-2025:10378 0 None None None 2025-07-07 07:24:35 UTC
Red Hat Product Errata RHSA-2025:10381 0 None None None 2025-07-07 08:10:20 UTC
Red Hat Product Errata RHSA-2025:10410 0 None None None 2025-07-07 12:22:59 UTC
Red Hat Product Errata RHSA-2025:9303 0 None None None 2025-06-23 02:50:53 UTC
Red Hat Product Errata RHSA-2025:9304 0 None None None 2025-06-23 01:27:35 UTC
Red Hat Product Errata RHSA-2025:9305 0 None None None 2025-06-23 02:36:06 UTC
Red Hat Product Errata RHSA-2025:9306 0 None None None 2025-06-23 01:58:29 UTC
Red Hat Product Errata RHSA-2025:9392 0 None None None 2025-06-23 14:05:25 UTC
Red Hat Product Errata RHSA-2025:9964 0 None None None 2025-06-30 13:47:18 UTC

Description OSIDB Bzimport 2025-06-03 07:20:47 UTC
nteger Overflow vulnerability in the Big Requests extension. The request length is multiplied before validation, allowing an overflow that defeats the size check, potentially leading to memory corruption.

Comment 4 errata-xmlrpc 2025-06-23 01:27:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:9304 https://access.redhat.com/errata/RHSA-2025:9304

Comment 5 errata-xmlrpc 2025-06-23 01:58:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:9306 https://access.redhat.com/errata/RHSA-2025:9306

Comment 6 errata-xmlrpc 2025-06-23 02:36:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:9305 https://access.redhat.com/errata/RHSA-2025:9305

Comment 7 errata-xmlrpc 2025-06-23 02:50:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:9303 https://access.redhat.com/errata/RHSA-2025:9303

Comment 8 errata-xmlrpc 2025-06-23 14:05:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:9392 https://access.redhat.com/errata/RHSA-2025:9392

Comment 9 errata-xmlrpc 2025-06-30 13:47:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:9964 https://access.redhat.com/errata/RHSA-2025:9964

Comment 10 errata-xmlrpc 2025-07-02 16:28:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:10258 https://access.redhat.com/errata/RHSA-2025:10258

Comment 11 errata-xmlrpc 2025-07-07 01:21:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:10348 https://access.redhat.com/errata/RHSA-2025:10348

Comment 12 errata-xmlrpc 2025-07-07 01:22:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support EXTENSION

Via RHSA-2025:10342 https://access.redhat.com/errata/RHSA-2025:10342

Comment 13 errata-xmlrpc 2025-07-07 01:23:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:10347 https://access.redhat.com/errata/RHSA-2025:10347

Comment 14 errata-xmlrpc 2025-07-07 01:31:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Extended Update Support EXTENSION
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:10343 https://access.redhat.com/errata/RHSA-2025:10343

Comment 15 errata-xmlrpc 2025-07-07 01:58:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service
  Red Hat Enterprise Linux 8.6 Extended Update Support EXTENSION

Via RHSA-2025:10346 https://access.redhat.com/errata/RHSA-2025:10346

Comment 16 errata-xmlrpc 2025-07-07 02:22:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service
  Red Hat Enterprise Linux 8.6 Extended Update Support EXTENSION

Via RHSA-2025:10344 https://access.redhat.com/errata/RHSA-2025:10344

Comment 17 errata-xmlrpc 2025-07-07 02:32:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:10360 https://access.redhat.com/errata/RHSA-2025:10360

Comment 18 errata-xmlrpc 2025-07-07 02:33:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:10352 https://access.redhat.com/errata/RHSA-2025:10352

Comment 19 errata-xmlrpc 2025-07-07 02:33:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support EXTENSION

Via RHSA-2025:10349 https://access.redhat.com/errata/RHSA-2025:10349

Comment 20 errata-xmlrpc 2025-07-07 02:37:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:10350 https://access.redhat.com/errata/RHSA-2025:10350

Comment 21 errata-xmlrpc 2025-07-07 02:41:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:10351 https://access.redhat.com/errata/RHSA-2025:10351

Comment 22 errata-xmlrpc 2025-07-07 02:42:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:10355 https://access.redhat.com/errata/RHSA-2025:10355

Comment 23 errata-xmlrpc 2025-07-07 02:45:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:10356 https://access.redhat.com/errata/RHSA-2025:10356

Comment 24 errata-xmlrpc 2025-07-07 05:29:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service
  Red Hat Enterprise Linux 8.8 Extended Update Support EXTENSION

Via RHSA-2025:10370 https://access.redhat.com/errata/RHSA-2025:10370

Comment 25 errata-xmlrpc 2025-07-07 07:18:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.7 Advanced Update Support

Via RHSA-2025:10376 https://access.redhat.com/errata/RHSA-2025:10376

Comment 26 errata-xmlrpc 2025-07-07 07:21:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:10375 https://access.redhat.com/errata/RHSA-2025:10375

Comment 27 errata-xmlrpc 2025-07-07 07:21:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:10374 https://access.redhat.com/errata/RHSA-2025:10374

Comment 28 errata-xmlrpc 2025-07-07 07:24:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:10378 https://access.redhat.com/errata/RHSA-2025:10378

Comment 29 errata-xmlrpc 2025-07-07 07:24:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION

Via RHSA-2025:10377 https://access.redhat.com/errata/RHSA-2025:10377

Comment 30 errata-xmlrpc 2025-07-07 08:10:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:10381 https://access.redhat.com/errata/RHSA-2025:10381

Comment 31 errata-xmlrpc 2025-07-07 12:22:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:10410 https://access.redhat.com/errata/RHSA-2025:10410


Note You need to log in before you can comment on or make changes to this bug.