Integer Overflow Vulnerability in RandR Extension of Affected Product by Red Hat
CVE-2025-49180

7.8HIGH

What is CVE-2025-49180?

An input validation flaw in the RRChangeProviderProperty function of the RandR extension can lead to an integer overflow. This issue occurs when calculating the total size for memory allocation, potentially allowing attackers to exploit this flaw to destabilize the application or lead to further security breaches.

Affected Version(s)

Red Hat Enterprise Linux 10 0:24.1.5-4.el10_0

Red Hat Enterprise Linux 8 0:1.20.11-26.el8_10

Red Hat Enterprise Linux 8 0:21.1.3-18.el8_10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49180 : Integer Overflow Vulnerability in RandR Extension of Affected Product by Red Hat