CVE-2025-49177
published 2025-06-17CVE-2025-49177: A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended…
PriorityP430medium6.1CVSS 3.1
AVLACLPRLUINSUCHINAL
EPSS
0.37%
29.3th percentile
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:21.1.7-3+deb12u10 (bookworm) | xorg-server 2:21.1.7-3+deb12u10 (bookworm) |
| debian | xwayland | < xorg-server 2:21.1.7-3+deb12u10 (bookworm) | xorg-server 2:21.1.7-3+deb12u10 (bookworm) |
| msrc | azl3_wayland_1.22.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_xorg-x11-server-xwayland_24.1.6-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0 | — | — |
| x.org | xorg-server | >= 0 < 2:21.1.7-3+deb12u10 | 2:21.1.7-3+deb12u10 |
| x.org | xorg-server | >= 0 < 2:21.1.16-1.2 | 2:21.1.16-1.2 |
| x.org | xorg-server | >= 0 < 2:21.1.16-1.2 | 2:21.1.16-1.2 |
| x.org | xwayland | < 24.1.7 | 24.1.7 |
| x.org | xwayland | >= 0 < 2:24.1.8-1 | 2:24.1.8-1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2025-06-17
CVE-2025-49176 X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
Nils Emmerich discovered that the X.Org X Server incorrectly handled
certain memory operations. An attacker could use these issues to cause the
X Server to crash, leading to a denial of service, obtain sensitive
information, or possibly execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Data Leak in XFIXES Extension's XFixesSetClientDisconnectMode
vendor_redhat·2025-06-17·CVSS 6.1
CVE-2025-49177 [MEDIUM] CWE-200 xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Data Leak in XFIXES Extension's XFixesSetClientDisconnectMode
xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Data Leak in XFIXES Extension's XFixesSetClientDisconnectMode
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
Statement: This vulnerability is rated as an important severity because the flaw exists in the XFIXES extension, specifically in the XFixesSetClientDisconnectMode handler. The handler does not validate the request length field correctly, allowing a client to read beyond the intended bounds of the inpu
Microsoft
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmode
vendor_msrc·2025-06-10·CVSS 5.5
CVE-2025-49177 [MEDIUM] CWE-200 Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmode
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmode
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Microsoft
hwrng: cavium - fix NULL but dereferenced coccicheck error
vendor_msrc·2025-02-11·CVSS 5.5
CVE-2022-49177 [MEDIUM] CWE-476 hwrng: cavium - fix NULL but dereferenced coccicheck error
hwrng: cavium - fix NULL but dereferenced coccicheck error
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Debian
CVE-2025-49177: xorg-server - A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode hand...
vendor_debian·2025·CVSS 6.1
CVE-2025-49177 [MEDIUM] CVE-2025-49177: xorg-server - A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode hand...
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u10)
bullseye: resolved
forky: resolved (fixed in 2:21.1.16-1.2)
sid: resolved (fixed in 2:21.1.16-1.2)
trixie: resolved (fixed in 2:21.1.16-1.2)
OSV
CVE-2025-49177: A flaw was found in the XFIXES extension
osv·2025-06-17·CVSS 6.1
CVE-2025-49177 [MEDIUM] CVE-2025-49177: A flaw was found in the XFIXES extension
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
GHSA
GHSA-pw35-9xmg-v8xw: A flaw was found in the XFIXES extension
ghsa_unreviewed·2025-06-17
CVE-2025-49177 [MEDIUM] CWE-200 GHSA-pw35-9xmg-v8xw: A flaw was found in the XFIXES extension
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2025:10258https://access.redhat.com/errata/RHSA-2025:9303https://access.redhat.com/errata/RHSA-2025:9304https://access.redhat.com/security/cve/CVE-2025-49177https://bugzilla.redhat.com/show_bug.cgi?id=2369955https://gitlab.freedesktop.org/xorg/xserver/-/commit/ab02fb96b1c701c3bb47617d965522c34befa6afhttps://www.x.org/wiki/Development/Security/
2025-06-17
Published