CVE Vulnerabilities

CVE-2025-49178

Improper Locking

Published: Jun 17, 2025 | Modified: Dec 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in the X servers request handling. Non-zero bytes to ignore in a clients request can cause the server to skip processing another clients request, potentially leading to a denial of service.

Weakness

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatxorg-x11-server-Xwayland-0:24.1.5-4.el10_0*
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONRedHattigervnc-0:1.1.0-25.el6_10.1*
Red Hat Enterprise Linux 7.7 Advanced Update SupportRedHattigervnc-0:1.8.0-17.el7_7.1*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatxorg-x11-server-0:1.20.4-32.el7_9*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHattigervnc-0:1.8.0-36.el7_9.2*
Red Hat Enterprise Linux 8RedHatxorg-x11-server-0:1.20.11-26.el8_10*
Red Hat Enterprise Linux 8RedHatxorg-x11-server-Xwayland-0:21.1.3-18.el8_10*
Red Hat Enterprise Linux 8RedHattigervnc-0:1.15.0-7.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHattigervnc-0:1.9.0-15.el8_2.14*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatxorg-x11-server-0:1.20.6-4.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatxorg-x11-server-0:1.20.10-2.el8_4*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHattigervnc-0:1.11.0-8.el8_4.13*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatxorg-x11-server-0:1.20.10-2.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHattigervnc-0:1.11.0-8.el8_4.13*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHattigervnc-0:1.12.0-6.el8_6.14*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatxorg-x11-server-Xwayland-0:21.1.3-2.el8_6.4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatxorg-x11-server-0:1.20.11-5.el8_6.3*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHattigervnc-0:1.12.0-6.el8_6.14*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHatxorg-x11-server-Xwayland-0:21.1.3-2.el8_6.4*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHattigervnc-0:1.12.0-6.el8_6.14*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatxorg-x11-server-Xwayland-0:21.1.3-2.el8_6.4*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatxorg-x11-server-0:1.20.11-5.el8_6.3*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHattigervnc-0:1.12.0-6.el8_6.14*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatxorg-x11-server-Xwayland-0:21.1.3-2.el8_6.4*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatxorg-x11-server-0:1.20.11-5.el8_6.3*
Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-OnRedHatxorg-x11-server-0:1.20.11-16.el8_8*
Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-OnRedHatxorg-x11-server-Xwayland-0:21.1.3-11.el8_8*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatxorg-x11-server-0:1.20.11-16.el8_8*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHattigervnc-0:1.12.0-15.el8_8.14*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatxorg-x11-server-Xwayland-0:21.1.3-11.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatxorg-x11-server-0:1.20.11-16.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHattigervnc-0:1.12.0-15.el8_8.14*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatxorg-x11-server-Xwayland-0:21.1.3-11.el8_8*
Red Hat Enterprise Linux 9RedHatxorg-x11-server-0:1.20.11-31.el9_6*
Red Hat Enterprise Linux 9RedHatxorg-x11-server-Xwayland-0:23.2.7-4.el9_6*
Red Hat Enterprise Linux 9RedHattigervnc-0:1.14.1-8.el9_6*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatxorg-x11-server-Xwayland-0:21.1.3-3.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatxorg-x11-server-0:1.20.11-11.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHattigervnc-0:1.11.0-22.el9_0.15*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatxorg-x11-server-Xwayland-0:21.1.3-8.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatxorg-x11-server-0:1.20.11-18.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHattigervnc-0:1.12.0-14.el9_2.12*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatxorg-x11-server-Xwayland-0:22.1.9-6.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatxorg-x11-server-0:1.20.11-26.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHattigervnc-0:1.13.1-8.el9_4.7*
Xorg-serverUbuntudevel*
Xorg-serverUbuntuesm-infra/bionic*
Xorg-serverUbuntuesm-infra/focal*
Xorg-serverUbuntuesm-infra/xenial*
Xorg-serverUbuntujammy*
Xorg-serverUbuntunoble*
Xorg-serverUbuntuoracular*
Xorg-serverUbuntuplucky*
Xorg-serverUbuntuquesting*
Xorg-serverUbuntuupstream*
Xorg-server-hwe-16.04Ubuntuesm-infra/xenial*
Xorg-server-hwe-18.04Ubuntuesm-infra/bionic*
XwaylandUbuntudevel*
XwaylandUbuntujammy*
XwaylandUbuntunoble*
XwaylandUbuntuoracular*
XwaylandUbuntuplucky*
XwaylandUbuntuquesting*
XwaylandUbuntuupstream*

Extended Description

Locking is a type of synchronization behavior that ensures that multiple independently-operating processes or threads do not interfere with each other when accessing the same resource. All processes/threads are expected to follow the same steps for locking. If these steps are not followed precisely - or if no locking is done at all - then another process/thread could modify the shared resource in a way that is not visible or predictable to the original process. This can lead to data or memory corruption, denial of service, etc.

Potential Mitigations

References