X.Org Server 21.1.18 update addressing 6 vulnerabilities

Correction releases for X.Org Server 21.1.17 and the DDX component (Device-Dependent X) xwayland 24.1.7 have been published, enabling the launch of X.Org Server for running X11 applications in Wayland-based environments. The new version of X.Org Server fixes 6 vulnerabilities. These issues may potentially be exploited for privilege escalation in systems where the X server runs with root privileges, as well as for remote code execution in configurations where access uses X11 session forwarding via SSH.

Identified vulnerabilities:

  • CVE-2025-49176 — an integer overflow leading to memory corruption in the implementation of the Big Requests extension, which allows sending requests exceeding 64 kilobytes. The vulnerability has been present since the release of X11R6.0 (1994).
  • CVE-2025-49179 — an integer overflow leading to memory corruption in the implementation of the X Record extension, occurring when sending excessively large client number or range values. The vulnerability has been present since the release of X11R6.1 (1996).
  • CVE-2025-49180 — an integer overflow leading to memory corruption in the implementation of the RandR extension. The vulnerability has been present since the release of 1.13 RC1 (2012).
  • CVE-2025-49178 — the potential for creating a situation that leads to blocking requests from other clients. The vulnerability has been present since the release of Xorg 1.10.0.
  • CVE-2025-49175 — reading from memory outside the buffer boundary in the X Rendering extension, occurring during operations with animated cursors. The vulnerability has been present since the release of XFree86 4.3.0 (2003).
  • CVE-2025-49177 — data leakage in the implementation of the XFIXES extension, caused by a lack of size checking for client requests in the XFixesSetClientDisconnectMode handler (the client may send a shorter request and read data from a previous request). The vulnerability has been present since the release of Xorg Server 21.1 RC1 (2021).

Additional: In response to these issues, releases of X.Org Server 21.1.18 and xwayland 24.1.8 have been created, which include additional changes to address the vulnerability CVE-2025-49176.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster