CVE-2025-49177
EUVD-2025-1849917.06.2025, 15:15
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| x.org | xwayland | 𝑥 < 24.1.7 | CNA |
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-server |
| ||||||||||||||||
| xwayland |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-server |
| ||||||||||||||||||||
| xwayland |
| ||||||||||||||||||||
| xorg |
| ||||||||||||||||||||
| xorg-server-hwe-16.04 |
| ||||||||||||||||||||
| xorg-server-hwe-18.04 |
| ||||||||||||||||||||
| xorg-hwe-16.04 |
| ||||||||||||||||||||
| xorg-hwe-18.04 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-x11-server |
| ||||||||||||||||
| xorg-x11-server-Xvfb |
| ||||||||||||||||
| xorg-x11-server-extra |
| ||||||||||||||||
| xorg-x11-server-sdk |
| ||||||||||||||||
| xwayland |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| xorg-x11-server-Xdmx |
| ||
| xorg-x11-server-Xephyr |
| ||
| xorg-x11-server-Xnest |
| ||
| xorg-x11-server-Xorg |
| ||
| xorg-x11-server-Xvfb |
| ||
| xorg-x11-server-Xwayland |
| ||
| xorg-x11-server-Xwayland-devel |
| ||
| xorg-x11-server-common |
| ||
| xorg-x11-server-devel |
| ||
| xorg-x11-server-source |
|
Common Weakness Enumeration
References