Information disclosure in X.org Server and Xwayland - CVE-2025-49177
Published: June 17, 2025
Vulnerability identifier: #VU111228
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49177
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a data leak in XFIXES Extension 6 (XFixesSetClientDisconnectMode). A local user can gain access to sensitive information.
Affected software
X.org Server
Xwayland
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Workstation Extension 15
OpenBSD
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Development Tools Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
tigervnc
xorg-x11-server-source
xorg-x11-server-devel
xorg-x11-server-common
xorg-x11-server-Xvfb
xorg-x11-server-Xorg
xorg-x11-server-Xnest
xorg-x11-server-Xephyr
xorg-x11-server-Xdmx
xorg-server (Ubuntu package)
xorg-x11-server-debuginfo
xorg-x11-server-extra
xorg-x11-server-Xvfb-debuginfo
xorg-x11-server-sdk
xorg-x11-server-debugsource
xorg-x11-server-extra-debuginfo
xorg-x11-server
xorg-server (Debian package)
xorg-x11-server-Xwayland (Red Hat package)
xorg-x11-server-Xwayland-devel
xorg-x11-server-Xwayland
xorg-x11-server-Xwayland-doc
xwayland
xwayland-devel
xwayland-debuginfo
xwayland-debugsource
Xwayland
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Workstation Extension 15
OpenBSD
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Development Tools Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
tigervnc
xorg-x11-server-source
xorg-x11-server-devel
xorg-x11-server-common
xorg-x11-server-Xvfb
xorg-x11-server-Xorg
xorg-x11-server-Xnest
xorg-x11-server-Xephyr
xorg-x11-server-Xdmx
xorg-server (Ubuntu package)
xorg-x11-server-debuginfo
xorg-x11-server-extra
xorg-x11-server-Xvfb-debuginfo
xorg-x11-server-sdk
xorg-x11-server-debugsource
xorg-x11-server-extra-debuginfo
xorg-x11-server
xorg-server (Debian package)
xorg-x11-server-Xwayland (Red Hat package)
xorg-x11-server-Xwayland-devel
xorg-x11-server-Xwayland
xorg-x11-server-Xwayland-doc
xwayland
xwayland-devel
xwayland-debuginfo
xwayland-debugsource
How to mitigate CVE-2025-49177
Install updates from vendor's website.
X.org Server - update to 21.1.17
Xwayland - update to 24.1.7
tigervnc - addressed in versions 1.15.0-6.fc41, 1.15.0-6.fc42
xorg-x11-server-source - update to 1.20.14-15
xorg-x11-server-devel - update to 1.20.14-15
xorg-x11-server-common - update to 1.20.14-15
xorg-x11-server-Xvfb - update to 1.20.14-15
xorg-x11-server-Xorg - update to 1.20.14-15
xorg-x11-server-Xnest - update to 1.20.14-15
xorg-x11-server-Xephyr - update to 1.20.14-15
xorg-x11-server-Xdmx - update to 1.20.14-15
xorg-server (Ubuntu package) - addressed in versions 2:21.1.4-2ubuntu1.7~22.04.15, 2:21.1.12-1ubuntu1.4, 2:21.1.13-2ubuntu1.4, 2:21.1.16-1ubuntu1.1, 2:22.1.1-1ubuntu0.19, 2:23.2.6-1ubuntu0.6, 2:24.1.2-1ubuntu0.6, 2:24.1.6-1ubuntu0.1
xorg-x11-server-debuginfo - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-extra - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-Xvfb - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-Xvfb-debuginfo - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-sdk - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-debugsource - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-extra-debuginfo - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-source - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1
xorg-x11-server - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-server (Debian package) - update to 2:21.1.7-3+deb12u10
xorg-x11-server - addressed in versions 21.1.17-1.fc41, 21.1.17-1.fc42, 21.1.18-1.fc41, 21.1.18-1.fc42
xorg-x11-server-Xwayland (Red Hat package) - addressed in versions 22.1.9-6.el9_4, 24.1.5-4.el10_0
xorg-x11-server-Xwayland-devel - update to 23.2.5-4
xorg-x11-server-Xwayland - update to 23.2.5-4
xorg-x11-server-Xwayland-doc - update to 23.2.5-4
xwayland - addressed in versions 24.1.1-150600.5.12.1, 24.1.5-150700.3.3.1
xwayland-devel - update to 24.1.1-150600.5.12.1
xwayland-debuginfo - addressed in versions 24.1.1-150600.5.12.1, 24.1.5-150700.3.3.1
xwayland-debugsource - addressed in versions 24.1.1-150600.5.12.1, 24.1.5-150700.3.3.1
xorg-x11-server-Xwayland - addressed in versions 24.1.7-1.fc41, 24.1.7-1.fc42, 24.1.8-1.fc41, 24.1.8-1.fc42
Xwayland - update to 24.1.7
tigervnc - addressed in versions 1.15.0-6.fc41, 1.15.0-6.fc42
xorg-x11-server-source - update to 1.20.14-15
xorg-x11-server-devel - update to 1.20.14-15
xorg-x11-server-common - update to 1.20.14-15
xorg-x11-server-Xvfb - update to 1.20.14-15
xorg-x11-server-Xorg - update to 1.20.14-15
xorg-x11-server-Xnest - update to 1.20.14-15
xorg-x11-server-Xephyr - update to 1.20.14-15
xorg-x11-server-Xdmx - update to 1.20.14-15
xorg-server (Ubuntu package) - addressed in versions 2:21.1.4-2ubuntu1.7~22.04.15, 2:21.1.12-1ubuntu1.4, 2:21.1.13-2ubuntu1.4, 2:21.1.16-1ubuntu1.1, 2:22.1.1-1ubuntu0.19, 2:23.2.6-1ubuntu0.6, 2:24.1.2-1ubuntu0.6, 2:24.1.6-1ubuntu0.1
xorg-x11-server-debuginfo - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-extra - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-Xvfb - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-Xvfb-debuginfo - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-sdk - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-debugsource - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-extra-debuginfo - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-x11-server-source - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1
xorg-x11-server - addressed in versions 21.1.4-150500.7.35.1, 21.1.11-150600.5.12.1, 21.1.15-150700.5.3.1
xorg-server (Debian package) - update to 2:21.1.7-3+deb12u10
xorg-x11-server - addressed in versions 21.1.17-1.fc41, 21.1.17-1.fc42, 21.1.18-1.fc41, 21.1.18-1.fc42
xorg-x11-server-Xwayland (Red Hat package) - addressed in versions 22.1.9-6.el9_4, 24.1.5-4.el10_0
xorg-x11-server-Xwayland-devel - update to 23.2.5-4
xorg-x11-server-Xwayland - update to 23.2.5-4
xorg-x11-server-Xwayland-doc - update to 23.2.5-4
xwayland - addressed in versions 24.1.1-150600.5.12.1, 24.1.5-150700.3.3.1
xwayland-devel - update to 24.1.1-150600.5.12.1
xwayland-debuginfo - addressed in versions 24.1.1-150600.5.12.1, 24.1.5-150700.3.3.1
xwayland-debugsource - addressed in versions 24.1.1-150600.5.12.1, 24.1.5-150700.3.3.1
xorg-x11-server-Xwayland - addressed in versions 24.1.7-1.fc41, 24.1.7-1.fc42, 24.1.8-1.fc41, 24.1.8-1.fc42
External References
Related Security Bulletins
- Multiple vulnerabilities in X.Org X server and Xwayland
- OpenBSD update for x.org server
- SUSE update for xwayland
- SUSE update for xwayland
- SUSE update for xorg-x11-server
- SUSE update for xorg-x11-server
- SUSE update for xorg-x11-server
- Ubuntu update for xorg-server
- Fedora 42 update for xorg-x11-server
- Fedora 41 update for xorg-x11-server
- Fedora 42 update for xorg-x11-server-Xwayland
- Fedora 41 update for xorg-x11-server-Xwayland
- Fedora 41 update for xorg-x11-server
- Fedora 41 update for tigervnc
- Fedora 42 update for tigervnc
- Debian update for xorg-server
- Fedora 42 update for xorg-x11-server-Xwayland
- Fedora 42 update for xorg-x11-server
- Fedora 41 update for xorg-x11-server-Xwayland
- Red Hat Enterprise Linux 10 update for xorg-x11-server-Xwayland
- Red Hat Enterprise Linux 9 update for xorg-x11-server-Xwayland
- OpenBSD update for X.org Server
- Anolis OS update for xorg-x11-server and xorg-x11-server-Xwayland