Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-49180

Published: June 18, 2025Last modified: June 25, 2025

Description

A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocate.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Notes

Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/3c3a4b767b16174d3213055947ea7f4f88e10ec6 Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/0235121c6a7a6eb247e2addb3b41ed6ef566853d

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSxorg-serverFixed (21.1.18-r0)
Streamxorg-serverFixed (21.1.17-r0)

References

ON THIS PAGE