Skip to main content
EPSS 0.3%top 76%

CVE-2025-49179: Integer Overflow or Wraparound in X.Org xwayland

0
High
VulnerabilityCVE-2025-49179cvecve-2025-49179
Published: 06/17/2025 (06/17/2025, 14:54:49 UTC)
Source: CVE Database V5
Vendor/Project: X.Org
Product: xwayland

Description

A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.

CVSS v3.1

Score 7.3high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

Affected software

Affected versions
=0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/02/2026, 21:56:21 UTC

Technical Analysis

An integer overflow vulnerability exists in the X Record extension within the xwayland component of X.Org. Specifically, the RecordSanityCheckRegisterClients function fails to check for integer overflow when computing the length of a client request, which can allow a client to bypass length validation checks. This vulnerability is tracked as CVE-2025-49179 with a CVSS 3.1 base score of 7.3 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H), indicating that a local attacker with low privileges can exploit this flaw to cause high impact on confidentiality and availability, and limited impact on integrity. Red Hat has released security advisories and patches for xorg-x11-server and xorg-x11-server-Xwayland packages in Red Hat Enterprise Linux 8.4 and 9.4 Extended Update Support to fix this and related vulnerabilities. The advisories confirm the availability of official fixes and provide instructions for applying updates.

Potential Impact

The vulnerability allows a local attacker with low privileges to bypass request length checks due to an integer overflow, potentially leading to high confidentiality and availability impact, and limited integrity impact. This could result in unauthorized access to sensitive information or denial of service conditions in the xwayland server environment. The CVSS score of 7.3 reflects the high severity of this issue.

Mitigation Recommendations

Official patches are available from Red Hat for affected versions of xorg-x11-server and xorg-x11-server-Xwayland in Red Hat Enterprise Linux 8.4 and 9.4 Extended Update Support. Users should apply these updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. No additional mitigations are specified by the vendor advisory. Patch status is confirmed as official-fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
redhat
Date Reserved
2025-06-03T05:38:02.947Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/errata/RHSA-2025:10258","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10342","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10343","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10344","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10346","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10347","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10348","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10349","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10350","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10351","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10352","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10355","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10356","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10360","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10370","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10374","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10375","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10376","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10377","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10378","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10381","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10410","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9303","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9304","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9305","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9306","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9392","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:9964","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-49179","vendor":"Red Hat"}]

Threat ID: 685183fca8c921274385da59

Added to database: 06/17/2025, 15:04:28 UTC

Last enriched: 07/02/2026, 21:56:21 UTC

Last updated: 09/10/2026, 19:36:50 UTC

Views: 127

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses