CVE-2025-49175

A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.
Configurations

No configuration.

History

23 Jun 2025, 19:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9303 -
  • () https://access.redhat.com/errata/RHSA-2025:9304 -
  • () https://access.redhat.com/errata/RHSA-2025:9305 -
  • () https://access.redhat.com/errata/RHSA-2025:9306 -
  • () https://access.redhat.com/errata/RHSA-2025:9392 -

23 Jun 2025, 07:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9303 -
  • () https://access.redhat.com/errata/RHSA-2025:9304 -
  • () https://access.redhat.com/errata/RHSA-2025:9305 -
  • () https://access.redhat.com/errata/RHSA-2025:9306 -
Summary
  • (es) Se detectó una falla en el manejo de cursores animados de la extensión X Rendering. Si un cliente no proporciona cursores, el servidor asume que hay al menos uno, lo que provoca una lectura fuera de los límites y un posible bloqueo.

17 Jun 2025, 20:50

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9303', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9304', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9305', 'source': 'secalert@redhat.com'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2025:9306', 'source': 'secalert@redhat.com'}

17 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 15:15

Updated : 2025-06-23 19:15


NVD link : CVE-2025-49175

Mitre link : CVE-2025-49175

CVE.ORG link : CVE-2025-49175


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read