Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 41 articles for you...
100

SUSE: 2025:02187-1 important: xwayland integer overflow

* bsc#1244084 Cross-References: * CVE-2025-49176 . # Security update for xwayland Announcement ID: SUSE-SU-2025:02187-1 Release Date: 2025-07-01T11:48:12Z Rating: important References: * bsc#1244084 Cross-References: * CVE-2025-49176 CVSS scores: * CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49176 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xwayland fixes the following issues: * CVE-2025-49176: Fixed the integer overflow in Big Requests Extension (bsc#1244084). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2025-2187=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * xwayland-24.1.5-150700.3.6.1 * xwayland-debugsource-24.1.5-150700.3.6.1 * xwayland-debuginfo-24.1.5-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49176.html * https://bugzilla.suse.com/show_bug.cgi?id=1244084 . This notification outlines an important enhancement for wayland-x relating to a critical data overflow vulnerability in SUSE. Immediate attention is necessary.. xwayland update, SUSE security, CVE-2025-49176 fix, integer overflow patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 01, 2025 Important SuSE
89

Fedora 41: FEDORA-2025-2363836c6c critical: xwayland X server multiple CVEs

Update to xwayland 24.1.8, contains an additional fix for CVE-2025-49176 Update to xserver 24.1.7, CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2363836c6c 2025-06-25 01:42:08.365124+00:00 -------------------------------------------------------------------------------- Name : xorg-x11-server-Xwayland Product : Fedora 41 Version : 24.1.8 Release : 1.fc41 URL : https://www.x.org/wiki/ Summary : Xwayland Description : Xwayland is an X server for running X clients under Wayland. -------------------------------------------------------------------------------- Update Information: Update to xwayland 24.1.8, contains an additional fix for CVE-2025-49176 Update to xserver 24.1.7, CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 18 2025 Olivier Fourdan - 24.1.8-1 - Update to xserver 24.1.8 - Contains an additional fix for CVE-2025-49176 * Tue Jun 17 2025 Olivier Fourdan - 24.1.7-1 - Update to xserver 24.1.7 - CVE fix for: CVE-2025-49175, CVE-2025-49176, CVE-2025-49177 CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2363836c6c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Essential patches for Fedora 41, tackling various CVEs impacting xwayland and xserver software modules.. Fedora security update,xwayland X server,CVE fix updates,important security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 25, 2025 Critical Fedora
172

Ubuntu 25.04: USN-7573-1 critical: xorg-server denial of service

Several security issues were fixed in X.Org X Server.. ========================================================================== Ubuntu Security Notice USN-7573-1 June 17, 2025 xorg-server, xwayland vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in X.Org X Server. Software Description: - xorg-server: X.Org X11 server - xwayland: X server for running X clients under Wayland Details: Nils Emmerich discovered that the X.Org X Server incorrectly handled certain memory operations. An attacker could use these issues to cause the X Server to crash, leading to a denial of service, obtain sensitive information, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 xserver-xorg-core 2:21.1.16-1ubuntu1.1 xwayland 2:24.1.6-1ubuntu0.1 Ubuntu 24.10 xserver-xorg-core 2:21.1.13-2ubuntu1.4 xwayland 2:24.1.2-1ubuntu0.6 Ubuntu 24.04 LTS xserver-xorg-core 2:21.1.12-1ubuntu1.4 xwayland 2:23.2.6-1ubuntu0.6 Ubuntu 22.04 LTS xserver-xorg-core 2:21.1.4-2ubuntu1.7~22.04.15 xwayland 2:22.1.1-1ubuntu0.19 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7573-1 CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 Package Information: https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.16-1ubuntu1.1 https://launchpad.net/ubuntu/+source/xwayland/2:24.1.6-1ubuntu0.1 https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.13-2ubuntu1.4 https://launchpad.net/ubuntu/+source/xwayland/2:24.1.2-1ubuntu0.6 https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.12-1ubuntu1.4 https://launchpad.net/ubuntu/+source/xwayland/2:23.2.6-1ubuntu0.6 https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.4-2ubuntu1.7~22.04.15 https://launchpad.net/ubuntu/+source/xwayland/2:22.1.1-1ubuntu0.19 . Urgent vulnerabilities in X.Org X Server necessitate prompt patches to avert service interruptions and unauthorized code execution risks.. X.Org X Server, Ubuntu updates, xwayland security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 17, 2025 Critical Ubuntu
100

SUSE: 2025:01974-1 critical: issues with Xwayland access functionality

* bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 . # Security update for xwayland Announcement ID: SUSE-SU-2025:01974-1 Release Date: 2025-06-17T15:28:44Z Rating: important References: * bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 * bsc#1244090 Cross-References: * CVE-2025-49175 * CVE-2025-49176 * CVE-2025-49177 * CVE-2025-49178 * CVE-2025-49179 * CVE-2025-49180 CVSS scores: * CVE-2025-49175 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49175 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-49175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49176 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-49177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49178 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49178 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49179 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49179 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49179 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49180 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49180 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49180 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues: * CVE-2025-49175: Out-of-bounds access in X Rendering extension (Animated cursors) (bsc#1244082). * CVE-2025-49176: Integer overflow in Big Requests Extension (bsc#1244084). * CVE-2025-49177: Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode) (bsc#1244085). * CVE-2025-49178: Unprocessed client request via bytes to ignore (bsc#1244087). * CVE-2025-49179: Integer overflow in X Record extension (bsc#1244089). * CVE-2025-49180: Integer overflow in RandR extension (RRChangeProviderProperty) (bsc#1244090). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1974=1 SUSE-2025-1974=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1974=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * xwayland-debuginfo-24.1.1-150600.5.12.1 * xwayland-debugsource-24.1.1-150600.5.12.1 * xwayland-24.1.1-150600.5.12.1 * xwayland-devel-24.1.1-150600.5.12.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * xwayland-debuginfo-24.1.1-150600.5.12.1 * xwayland-debugsource-24.1.1-150600.5.12.1 * xwayland-24.1.1-150600.5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49175.html * https://www.suse.com/security/cve/CVE-2025-49176.html * https://www.suse.com/security/cve/CVE-2025-49177.html * https://www.suse.com/security/cve/CVE-2025-49178.html *https://www.suse.com/security/cve/CVE-2025-49179.html * https://www.suse.com/security/cve/CVE-2025-49180.html * https://bugzilla.suse.com/show_bug.cgi?id=1244082 * https://bugzilla.suse.com/show_bug.cgi?id=1244084 * https://bugzilla.suse.com/show_bug.cgi?id=1244085 * https://bugzilla.suse.com/show_bug.cgi?id=1244087 * https://bugzilla.suse.com/show_bug.cgi?id=1244089 * https://bugzilla.suse.com/show_bug.cgi?id=1244090 . A significant security patch from SUSE addresses critical vulnerabilities in xwayland, mitigating various CVE risks. Installation is advised.. SUSE security,xwayland update,important security fix,SUSE Linux vulnerabilities,system access issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 17, 2025 Important SuSE
202

openSUSE Leap 15.6: 2025:01974-1 important: xwayland integer overflow

An update that solves six vulnerabilities can now be installed.. # Security update for xwayland Announcement ID: SUSE-SU-2025:01974-1 Release Date: 2025-06-17T15:28:44Z Rating: important References: * bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 * bsc#1244090 Cross-References: * CVE-2025-49175 * CVE-2025-49176 * CVE-2025-49177 * CVE-2025-49178 * CVE-2025-49179 * CVE-2025-49180 CVSS scores: * CVE-2025-49175 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49175 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-49175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49176 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-49177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49178 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49178 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49179 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49179 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49179 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49180 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49180 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49180 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H Affected Products: *openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues: * CVE-2025-49175: Out-of-bounds access in X Rendering extension (Animated cursors) (bsc#1244082). * CVE-2025-49176: Integer overflow in Big Requests Extension (bsc#1244084). * CVE-2025-49177: Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode) (bsc#1244085). * CVE-2025-49178: Unprocessed client request via bytes to ignore (bsc#1244087). * CVE-2025-49179: Integer overflow in X Record extension (bsc#1244089). * CVE-2025-49180: Integer overflow in RandR extension (RRChangeProviderProperty) (bsc#1244090). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1974=1 SUSE-2025-1974=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1974=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * xwayland-debuginfo-24.1.1-150600.5.12.1 * xwayland-debugsource-24.1.1-150600.5.12.1 * xwayland-24.1.1-150600.5.12.1 * xwayland-devel-24.1.1-150600.5.12.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * xwayland-debuginfo-24.1.1-150600.5.12.1 * xwayland-debugsource-24.1.1-150600.5.12.1 * xwayland-24.1.1-150600.5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49175.html * https://www.suse.com/security/cve/CVE-2025-49176.html * https://www.suse.com/security/cve/CVE-2025-49177.html * https://www.suse.com/security/cve/CVE-2025-49178.html *https://www.suse.com/security/cve/CVE-2025-49179.html * https://www.suse.com/security/cve/CVE-2025-49180.html * https://bugzilla.suse.com/show_bug.cgi?id=1244082 * https://bugzilla.suse.com/show_bug.cgi?id=1244084 * https://bugzilla.suse.com/show_bug.cgi?id=1244085 * https://bugzilla.suse.com/show_bug.cgi?id=1244087 * https://bugzilla.suse.com/show_bug.cgi?id=1244089 * https://bugzilla.suse.com/show_bug.cgi?id=1244090 . This crucial announcement highlights various safety vulnerabilities in xwayland for openSUSE, strengthening the system's defenses.. openSUSE security update,xwayland integer overflow,data leak issues,SUSE patch installation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 17, 2025 Important OpenSUSE
100

SUSE: 2025:01975-1 important: xwayland integer overflow issues

* bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 . # Security update for xwayland Announcement ID: SUSE-SU-2025:01975-1 Release Date: 2025-06-17T15:28:53Z Rating: important References: * bsc#1244082 * bsc#1244084 * bsc#1244085 * bsc#1244087 * bsc#1244089 * bsc#1244090 Cross-References: * CVE-2025-49175 * CVE-2025-49176 * CVE-2025-49177 * CVE-2025-49178 * CVE-2025-49179 * CVE-2025-49180 CVSS scores: * CVE-2025-49175 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49175 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-49175 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49176 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-49177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49178 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49178 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49179 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49179 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49179 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-49180 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-49180 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-49180 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues: * CVE-2025-49175: Out-of-bounds access in X Rendering extension (Animated cursors) (bsc#1244082) * CVE-2025-49176: Integer overflow in Big Requests Extension (bsc#1244084) * CVE-2025-49177: Data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode) (bsc#1244085) * CVE-2025-49178: Unprocessed client request via bytes to ignore (bsc#1244087) * CVE-2025-49179: Integer overflow in X Record extension (bsc#1244089) * CVE-2025-49180: Integer overflow in RandR extension (RRChangeProviderProperty) (bsc#1244090) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2025-1975=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * xwayland-debugsource-24.1.5-150700.3.3.1 * xwayland-debuginfo-24.1.5-150700.3.3.1 * xwayland-24.1.5-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49175.html * https://www.suse.com/security/cve/CVE-2025-49176.html * https://www.suse.com/security/cve/CVE-2025-49177.html * https://www.suse.com/security/cve/CVE-2025-49178.html * https://www.suse.com/security/cve/CVE-2025-49179.html * https://www.suse.com/security/cve/CVE-2025-49180.html * https://bugzilla.suse.com/show_bug.cgi?id=1244082 * https://bugzilla.suse.com/show_bug.cgi?id=1244084 * https://bugzilla.suse.com/show_bug.cgi?id=1244085 * https://bugzilla.suse.com/show_bug.cgi?id=1244087 *https://bugzilla.suse.com/show_bug.cgi?id=1244089 * https://bugzilla.suse.com/show_bug.cgi?id=1244090 . Xwayland's latest update addresses critical vulnerabilities, enhancing overall safety with multiple suggested setup techniques to elevate system robustness.. Xwayland Update, SUSE Security Patch, Important Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 17, 2025 Important SuSE
91

Gentoo: GLSA-202506-04 high: X.Org X server, XWayland exploit risk

A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202506-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: X.Org X server, XWayland: Multiple Vulnerabilities Date: June 12, 2025 Bugs: #950290 ID: 202506-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation. Background ========== The X Window System is a graphical windowing system based on a client/server model. Affected packages ================= Package Vulnerable Unaffected -------------------- ------------ ------------ x11-base/xorg-server < 21.1.16 > = 21.1.16 x11-base/xwayland < 24.1.6 > = 24.1.6 Description =========== Multiple vulnerabilities have been discovered in X.Org X server and XWayland. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All X.Org X server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-base/xorg-server-21.1.16" All XWayland users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-base/xwayland-24.1.6" References ========== [ 1 ] CVE-2025-26594 https://nvd.nist.gov/vuln/detail/CVE-2025-26594 [ 2 ] CVE-2025-26595 https://nvd.nist.gov/vuln/detail/CVE-2025-26595 [ 3 ] CVE-2025-26596 https://nvd.nist.gov/vuln/detail/CVE-2025-26596 [ 4 ] CVE-2025-26597 https://nvd.nist.gov/vuln/detail/CVE-2025-26597 [ 5 ] CVE-2025-26598 https://nvd.nist.gov/vuln/detail/CVE-2025-26598 [ 6 ] CVE-2025-26599 https://nvd.nist.gov/vuln/detail/CVE-2025-26599 [ 7 ] CVE-2025-26600 https://nvd.nist.gov/vuln/detail/CVE-2025-26600 [ 8 ] CVE-2025-26601 https://nvd.nist.gov/vuln/detail/CVE-2025-26601 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202506-04 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2025 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Several critical vulnerabilities in the X.Org X server and XWayland of Gentoo necessitate urgent patches.. Xorg Server, XWayland, Gentoo Security, Privilege Escalation, High Severity. . LinuxSecurity.com Team

Calendar%202 Jun 12, 2025 Gentoo
89

Fedora 42: xorg-x11-server-Xwayland 2025-065909f8c6 Security Advisory Updates

xwayland 24.1.6 CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-065909f8c6 2025-03-15 00:23:42.170070+00:00 -------------------------------------------------------------------------------- Name : xorg-x11-server-Xwayland Product : Fedora 42 Version : 24.1.6 Release : 1.fc42 URL : https://www.x.org/wiki/ Summary : Xwayland Description : Xwayland is an X server for running X clients under Wayland. -------------------------------------------------------------------------------- Update Information: xwayland 24.1.6 CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 Olivier Fourdan - 24.1.6-1 - xwayland 24.1.6 (#2343992) - CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2343992 - xorg-x11-server-Xwayland-24.1.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2343992 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-065909f8c6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Critical CVE updates for xwayland 24.1.6 in Fedora 42 with multiple security fixes.. xwayland, cve-2025-26594, cve-2025-26595, cve-2025-26596, cve-2025-26597, cve-202. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 15, 2025 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200