Memory Read Flaw in XFIXES Extension for Affected Products
CVE-2025-49177
Key Information:
- Vendor
X.org
- Status
- Vendor
- CVE Published:
- 17 June 2025
What is CVE-2025-49177?
A flaw exists in the XFIXES extension, where the XFixesSetClientDisconnectMode handler fails to properly validate the length of requests. This oversight allows a potential attacker to exploit the vulnerability, enabling them to access unintended memory from previous requests. Such an exploit could result in the exposure of sensitive information, leading to potential data breaches and compromised system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat Enterprise Linux 10 0:24.1.5-4.el10_0
Red Hat Enterprise Linux 9 0:1.20.11-31.el9_6
Red Hat Enterprise Linux 9 0:23.2.7-4.el9_6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
