CVE Vulnerabilities

CVE-2025-49178

Improper Locking

Published: Jun 17, 2025 | Modified: Jul 07, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A flaw was found in the X servers request handling. Non-zero bytes to ignore in a clients request can cause the server to skip processing another clients request, potentially leading to a denial of service.

Weakness

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat xorg-x11-server-Xwayland-0:24.1.5-4.el10_0 *
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION RedHat tigervnc-0:1.1.0-25.el6_10.1 *
Red Hat Enterprise Linux 7.7 Advanced Update Support RedHat tigervnc-0:1.8.0-17.el7_7.1 *
Red Hat Enterprise Linux 7 Extended Lifecycle Support RedHat xorg-x11-server-0:1.20.4-32.el7_9 *
Red Hat Enterprise Linux 7 Extended Lifecycle Support RedHat tigervnc-0:1.8.0-36.el7_9.2 *
Red Hat Enterprise Linux 8 RedHat xorg-x11-server-0:1.20.11-26.el8_10 *
Red Hat Enterprise Linux 8 RedHat xorg-x11-server-Xwayland-0:21.1.3-18.el8_10 *
Red Hat Enterprise Linux 8 RedHat tigervnc-0:1.15.0-7.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat tigervnc-0:1.9.0-15.el8_2.14 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat xorg-x11-server-0:1.20.6-4.el8_2 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat xorg-x11-server-0:1.20.10-2.el8_4 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat tigervnc-0:1.11.0-8.el8_4.13 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat xorg-x11-server-0:1.20.10-2.el8_4 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat tigervnc-0:1.11.0-8.el8_4.13 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat tigervnc-0:1.12.0-6.el8_6.14 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.4 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat xorg-x11-server-0:1.20.11-5.el8_6.3 *
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On RedHat tigervnc-0:1.12.0-6.el8_6.14 *
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On RedHat xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.4 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat tigervnc-0:1.12.0-6.el8_6.14 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.4 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat xorg-x11-server-0:1.20.11-5.el8_6.3 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat tigervnc-0:1.12.0-6.el8_6.14 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat xorg-x11-server-Xwayland-0:21.1.3-2.el8_6.4 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat xorg-x11-server-0:1.20.11-5.el8_6.3 *
Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-On RedHat xorg-x11-server-0:1.20.11-16.el8_8 *
Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-On RedHat xorg-x11-server-Xwayland-0:21.1.3-11.el8_8 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat xorg-x11-server-0:1.20.11-16.el8_8 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat tigervnc-0:1.12.0-15.el8_8.14 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat xorg-x11-server-Xwayland-0:21.1.3-11.el8_8 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat xorg-x11-server-0:1.20.11-16.el8_8 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat tigervnc-0:1.12.0-15.el8_8.14 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat xorg-x11-server-Xwayland-0:21.1.3-11.el8_8 *
Red Hat Enterprise Linux 9 RedHat xorg-x11-server-0:1.20.11-31.el9_6 *
Red Hat Enterprise Linux 9 RedHat xorg-x11-server-Xwayland-0:23.2.7-4.el9_6 *
Red Hat Enterprise Linux 9 RedHat tigervnc-0:1.14.1-8.el9_6 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat xorg-x11-server-Xwayland-0:21.1.3-3.el9_0 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat xorg-x11-server-0:1.20.11-11.el9_0 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat tigervnc-0:1.11.0-22.el9_0.15 *
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions RedHat xorg-x11-server-Xwayland-0:21.1.3-8.el9_2 *
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions RedHat xorg-x11-server-0:1.20.11-18.el9_2 *
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions RedHat tigervnc-0:1.12.0-14.el9_2.12 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat xorg-x11-server-Xwayland-0:22.1.9-6.el9_4 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat xorg-x11-server-0:1.20.11-26.el9_4 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat tigervnc-0:1.13.1-8.el9_4.7 *
Xorg-server Ubuntu devel *
Xorg-server Ubuntu esm-infra/bionic *
Xorg-server Ubuntu esm-infra/focal *
Xorg-server Ubuntu esm-infra/xenial *
Xorg-server Ubuntu jammy *
Xorg-server Ubuntu noble *
Xorg-server Ubuntu oracular *
Xorg-server Ubuntu plucky *
Xorg-server Ubuntu upstream *
Xorg-server-hwe-16.04 Ubuntu esm-infra/xenial *
Xorg-server-hwe-18.04 Ubuntu esm-infra/bionic *
Xwayland Ubuntu devel *
Xwayland Ubuntu jammy *
Xwayland Ubuntu noble *
Xwayland Ubuntu oracular *
Xwayland Ubuntu plucky *
Xwayland Ubuntu upstream *

Extended Description

Locking is a type of synchronization behavior that ensures that multiple independently-operating processes or threads do not interfere with each other when accessing the same resource. All processes/threads are expected to follow the same steps for locking. If these steps are not followed precisely - or if no locking is done at all - then another process/thread could modify the shared resource in a way that is not visible or predictable to the original process. This can lead to data or memory corruption, denial of service, etc.

Potential Mitigations

References