Untriaged
Permalink
CVE-2025-49176
6.6 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): HIGH
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension
A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
References
Affected products
tigervnc
- *
xwayland
- <24.1.7
xorg-x11-server
- *
xorg-x11-server-Xwayland
- *