Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1244084 Cross-References: * CVE-2025-49176 . # Security update for xwayland Announcement ID: SUSE-SU-2025:02187-1 Release Date: 2025-07-01T11:48:12Z Rating: important References: * bsc#1244084 Cross-References: * CVE-2025-49176 CVSS scores: * CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49176 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xwayland fixes the following issues: * CVE-2025-49176: Fixed the integer overflow in Big Requests Extension (bsc#1244084). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2025-2187=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * xwayland-24.1.5-150700.3.6.1 * xwayland-debugsource-24.1.5-150700.3.6.1 * xwayland-debuginfo-24.1.5-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49176.html * https://bugzilla.suse.com/show_bug.cgi?id=1244084 . This notification outlines an important enhancement for wayland-x relating to a critical data overflow vulnerability in SUSE. Immediate attention is necessary.. xwayland update, SUSE security, CVE-2025-49176 fix, integer overflow patch. . Severity: Important. LinuxSecurity.com Team
Update to xwayland 24.1.8, contains an additional fix for CVE-2025-49176 Update to xserver 24.1.7, CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2363836c6c 2025-06-25 01:42:08.365124+00:00 -------------------------------------------------------------------------------- Name : xorg-x11-server-Xwayland Product : Fedora 41 Version : 24.1.8 Release : 1.fc41 URL : https://www.x.org/wiki/ Summary : Xwayland Description : Xwayland is an X server for running X clients under Wayland. -------------------------------------------------------------------------------- Update Information: Update to xwayland 24.1.8, contains an additional fix for CVE-2025-49176 Update to xserver 24.1.7, CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 18 2025 Olivier Fourdan - 24.1.8-1 - Update to xserver 24.1.8 - Contains an additional fix for CVE-2025-49176 * Tue Jun 17 2025 Olivier Fourdan - 24.1.7-1 - Update to xserver 24.1.7 - CVE fix for: CVE-2025-49175, CVE-2025-49176, CVE-2025-49177 CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2363836c6c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in X.Org X Server.. ========================================================================== Ubuntu Security Notice USN-7573-1 June 17, 2025 xorg-server, xwayland vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in X.Org X Server. Software Description: - xorg-server: X.Org X11 server - xwayland: X server for running X clients under Wayland Details: Nils Emmerich discovered that the X.Org X Server incorrectly handled certain memory operations. An attacker could use these issues to cause the X Server to crash, leading to a denial of service, obtain sensitive information, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 xserver-xorg-core 2:21.1.16-1ubuntu1.1 xwayland 2:24.1.6-1ubuntu0.1 Ubuntu 24.10 xserver-xorg-core 2:21.1.13-2ubuntu1.4 xwayland 2:24.1.2-1ubuntu0.6 Ubuntu 24.04 LTS xserver-xorg-core 2:21.1.12-1ubuntu1.4 xwayland 2:23.2.6-1ubuntu0.6 Ubuntu 22.04 LTS xserver-xorg-core 2:21.1.4-2ubuntu1.7~22.04.15 xwayland 2:22.1.1-1ubuntu0.19 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7573-1 CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 Package Information: https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.16-1ubuntu1.1 https://launchpad.net/ubuntu/+source/xwayland/2:24.1.6-1ubuntu0.1 https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.13-2ubuntu1.4 https://launchpad.net/ubuntu/+source/xwayland/2:24.1.2-1ubuntu0.6 https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.12-1ubuntu1.4 https://launchpad.net/ubuntu/+source/xwayland/2:23.2.6-1ubuntu0.6 https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.4-2ubuntu1.7~22.04.15 https://launchpad.net/ubuntu/+source/xwayland/2:22.1.1-1ubuntu0.19 . Urgent vulnerabilities in X.Org X Server necessitate prompt patches to avert service interruptions and unauthorized code execution risks.. X.Org X Server, Ubuntu updates, xwayland security. . Severity: Critical. LinuxSecurity.com Team
* bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 . # Security update for xwayland Announcement ID: SUSE-SU-2025:01974-1 Release Date: 2025-06-17T15:28:44Z Rating: important References: * bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 * bsc#1244090 Cross-References: * CVE-2025-49175 * CVE-2025-49176 * CVE-2025-49177 * CVE-2025-49178 * CVE-2025-49179 * CVE-2025-49180 CVSS scores: * CVE-2025-49175 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49175 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-49175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49176 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-49177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49178 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49178 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49179 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49179 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49179 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49180 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49180 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49180 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues: * CVE-2025-49175: Out-of-bounds access in X Rendering extension (Animated cursors) (bsc#1244082). * CVE-2025-49176: Integer overflow in Big Requests Extension (bsc#1244084). * CVE-2025-49177: Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode) (bsc#1244085). * CVE-2025-49178: Unprocessed client request via bytes to ignore (bsc#1244087). * CVE-2025-49179: Integer overflow in X Record extension (bsc#1244089). * CVE-2025-49180: Integer overflow in RandR extension (RRChangeProviderProperty) (bsc#1244090). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1974=1 SUSE-2025-1974=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1974=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * xwayland-debuginfo-24.1.1-150600.5.12.1 * xwayland-debugsource-24.1.1-150600.5.12.1 * xwayland-24.1.1-150600.5.12.1 * xwayland-devel-24.1.1-150600.5.12.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * xwayland-debuginfo-24.1.1-150600.5.12.1 * xwayland-debugsource-24.1.1-150600.5.12.1 * xwayland-24.1.1-150600.5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49175.html * https://www.suse.com/security/cve/CVE-2025-49176.html * https://www.suse.com/security/cve/CVE-2025-49177.html * https://www.suse.com/security/cve/CVE-2025-49178.html *https://www.suse.com/security/cve/CVE-2025-49179.html * https://www.suse.com/security/cve/CVE-2025-49180.html * https://bugzilla.suse.com/show_bug.cgi?id=1244082 * https://bugzilla.suse.com/show_bug.cgi?id=1244084 * https://bugzilla.suse.com/show_bug.cgi?id=1244085 * https://bugzilla.suse.com/show_bug.cgi?id=1244087 * https://bugzilla.suse.com/show_bug.cgi?id=1244089 * https://bugzilla.suse.com/show_bug.cgi?id=1244090 . A significant security patch from SUSE addresses critical vulnerabilities in xwayland, mitigating various CVE risks. Installation is advised.. SUSE security,xwayland update,important security fix,SUSE Linux vulnerabilities,system access issues. . Severity: Important. LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for xwayland Announcement ID: SUSE-SU-2025:01974-1 Release Date: 2025-06-17T15:28:44Z Rating: important References: * bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 * bsc#1244090 Cross-References: * CVE-2025-49175 * CVE-2025-49176 * CVE-2025-49177 * CVE-2025-49178 * CVE-2025-49179 * CVE-2025-49180 CVSS scores: * CVE-2025-49175 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49175 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-49175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49176 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-49177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49178 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49178 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49179 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49179 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49179 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49180 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49180 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49180 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H Affected Products: *openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues: * CVE-2025-49175: Out-of-bounds access in X Rendering extension (Animated cursors) (bsc#1244082). * CVE-2025-49176: Integer overflow in Big Requests Extension (bsc#1244084). * CVE-2025-49177: Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode) (bsc#1244085). * CVE-2025-49178: Unprocessed client request via bytes to ignore (bsc#1244087). * CVE-2025-49179: Integer overflow in X Record extension (bsc#1244089). * CVE-2025-49180: Integer overflow in RandR extension (RRChangeProviderProperty) (bsc#1244090). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1974=1 SUSE-2025-1974=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1974=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * xwayland-debuginfo-24.1.1-150600.5.12.1 * xwayland-debugsource-24.1.1-150600.5.12.1 * xwayland-24.1.1-150600.5.12.1 * xwayland-devel-24.1.1-150600.5.12.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * xwayland-debuginfo-24.1.1-150600.5.12.1 * xwayland-debugsource-24.1.1-150600.5.12.1 * xwayland-24.1.1-150600.5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49175.html * https://www.suse.com/security/cve/CVE-2025-49176.html * https://www.suse.com/security/cve/CVE-2025-49177.html * https://www.suse.com/security/cve/CVE-2025-49178.html *https://www.suse.com/security/cve/CVE-2025-49179.html * https://www.suse.com/security/cve/CVE-2025-49180.html * https://bugzilla.suse.com/show_bug.cgi?id=1244082 * https://bugzilla.suse.com/show_bug.cgi?id=1244084 * https://bugzilla.suse.com/show_bug.cgi?id=1244085 * https://bugzilla.suse.com/show_bug.cgi?id=1244087 * https://bugzilla.suse.com/show_bug.cgi?id=1244089 * https://bugzilla.suse.com/show_bug.cgi?id=1244090 . This crucial announcement highlights various safety vulnerabilities in xwayland for openSUSE, strengthening the system's defenses.. openSUSE security update,xwayland integer overflow,data leak issues,SUSE patch installation. . Severity: Important. LinuxSecurity.com Team
* bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 . # Security update for xwayland Announcement ID: SUSE-SU-2025:01975-1 Release Date: 2025-06-17T15:28:53Z Rating: important References: * bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 * bsc#1244090 Cross-References: * CVE-2025-49175 * CVE-2025-49176 * CVE-2025-49177 * CVE-2025-49178 * CVE-2025-49179 * CVE-2025-49180 CVSS scores: * CVE-2025-49175 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49175 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-49175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49176 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-49177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49178 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49178 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49179 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49179 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49179 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49180 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49180 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49180 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues: * CVE-2025-49175: Out-of-bounds access in X Rendering extension (Animated cursors) (bsc#1244082) * CVE-2025-49176: Integer overflow in Big Requests Extension (bsc#1244084) * CVE-2025-49177: Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode) (bsc#1244085) * CVE-2025-49178: Unprocessed client request via bytes to ignore (bsc#1244087) * CVE-2025-49179: Integer overflow in X Record extension (bsc#1244089) * CVE-2025-49180: Integer overflow in RandR extension (RRChangeProviderProperty) (bsc#1244090) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2025-1975=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * xwayland-debugsource-24.1.5-150700.3.3.1 * xwayland-debuginfo-24.1.5-150700.3.3.1 * xwayland-24.1.5-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49175.html * https://www.suse.com/security/cve/CVE-2025-49176.html * https://www.suse.com/security/cve/CVE-2025-49177.html * https://www.suse.com/security/cve/CVE-2025-49178.html * https://www.suse.com/security/cve/CVE-2025-49179.html * https://www.suse.com/security/cve/CVE-2025-49180.html * https://bugzilla.suse.com/show_bug.cgi?id=1244082 * https://bugzilla.suse.com/show_bug.cgi?id=1244084 * https://bugzilla.suse.com/show_bug.cgi?id=1244085 * https://bugzilla.suse.com/show_bug.cgi?id=1244087 *https://bugzilla.suse.com/show_bug.cgi?id=1244089 * https://bugzilla.suse.com/show_bug.cgi?id=1244090 . Xwayland's latest update addresses critical vulnerabilities, enhancing overall safety with multiple suggested setup techniques to elevate system robustness.. Xwayland Update, SUSE Security Patch, Important Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team
A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202506-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: X.Org X server, XWayland: Multiple Vulnerabilities Date: June 12, 2025 Bugs: #950290 ID: 202506-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation. Background ========== The X Window System is a graphical windowing system based on a client/server model. Affected packages ================= Package Vulnerable Unaffected -------------------- ------------ ------------ x11-base/xorg-server < 21.1.16 > = 21.1.16 x11-base/xwayland < 24.1.6 > = 24.1.6 Description =========== Multiple vulnerabilities have been discovered in X.Org X server and XWayland. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All X.Org X server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-base/xorg-server-21.1.16" All XWayland users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-base/xwayland-24.1.6" References ========== [ 1 ] CVE-2025-26594 https://nvd.nist.gov/vuln/detail/CVE-2025-26594 [ 2 ] CVE-2025-26595 https://nvd.nist.gov/vuln/detail/CVE-2025-26595 [ 3 ] CVE-2025-26596 https://nvd.nist.gov/vuln/detail/CVE-2025-26596 [ 4 ] CVE-2025-26597 https://nvd.nist.gov/vuln/detail/CVE-2025-26597 [ 5 ] CVE-2025-26598 https://nvd.nist.gov/vuln/detail/CVE-2025-26598 [ 6 ] CVE-2025-26599 https://nvd.nist.gov/vuln/detail/CVE-2025-26599 [ 7 ] CVE-2025-26600 https://nvd.nist.gov/vuln/detail/CVE-2025-26600 [ 8 ] CVE-2025-26601 https://nvd.nist.gov/vuln/detail/CVE-2025-26601 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202506-04 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
xwayland 24.1.6 CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-065909f8c6 2025-03-15 00:23:42.170070+00:00 -------------------------------------------------------------------------------- Name : xorg-x11-server-Xwayland Product : Fedora 42 Version : 24.1.6 Release : 1.fc42 URL : https://www.x.org/wiki/ Summary : Xwayland Description : Xwayland is an X server for running X clients under Wayland. -------------------------------------------------------------------------------- Update Information: xwayland 24.1.6 CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 Olivier Fourdan - 24.1.6-1 - xwayland 24.1.6 (#2343992) - CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2343992 - xorg-x11-server-Xwayland-24.1.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2343992 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-065909f8c6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.