CVE-2025-49177

Updated: 2026-02-27 02:52:58.965229

Description:

A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 6.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU xorg-x11-server-Xwayland 21.1.3 6.1 MEDIUM Ignored 2025-10-28 00:24:54 This flaw exists only in the X.Org X server/Xwayland XFIXES extension and is exploitable by a local,...