CVE-2025-49177: Red Hat Enterprise Linux 10
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:24.1.5-4.el10_0 (fixed in 0:24.1.5-4.el10_0)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 0:1.20.11-31.el9_6 (fixed in 0:1.20.11-31.el9_6); before 0:23.2.7-4.el9_6 (fixed in 0:23.2.7-4.el9_6)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:22.1.9-6.el9_4 (fixed in 0:22.1.9-6.el9_4)
- X.org Xwayland: before 24.1.7 (fixed in 24.1.7)
Published 2025-06-17. Last modified 2026-06-30.