Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:10343 - Security Advisory
Issued:
2025-07-07
Updated:
2025-07-07

RHSA-2025:10343 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: xorg-x11-server security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for xorg-x11-server is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Extended Update Support EXTENSION, and Red Hat Enterprise Linux 8.8 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.

Security Fix(es):

  • xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Out-of-Bounds Read in X Rendering Extension Animated Cursors (CVE-2025-49175)
  • xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer Overflow in Big Requests Extension (CVE-2025-49176)
  • xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Unprocessed Client Request Due to Bytes to Ignore (CVE-2025-49178)
  • xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer overflow in X Record extension (CVE-2025-49179)
  • xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer Overflow in X Resize, Rotate and Reflect (RandR) Extension (CVE-2025-49180)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2369947 - CVE-2025-49175 xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Out-of-Bounds Read in X Rendering Extension Animated Cursors
  • BZ - 2369954 - CVE-2025-49176 xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer Overflow in Big Requests Extension
  • BZ - 2369977 - CVE-2025-49178 xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Unprocessed Client Request Due to Bytes to Ignore
  • BZ - 2369978 - CVE-2025-49179 xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer overflow in X Record extension
  • BZ - 2369981 - CVE-2025-49180 xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer Overflow in X Resize, Rotate and Reflect (RandR) Extension

CVEs

  • CVE-2025-49175
  • CVE-2025-49176
  • CVE-2025-49178
  • CVE-2025-49179
  • CVE-2025-49180

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8

SRPM
xorg-x11-server-1.20.11-16.el8_8.src.rpm SHA-256: 22e036a0f9a0ef0977743eead59cadbf68264ec872f08015729ddf3b8a826912
x86_64
xorg-x11-server-Xdmx-1.20.11-16.el8_8.x86_64.rpm SHA-256: 85736e34f010a5e01f13e8f4a691719b2e446a30bb487933e38dd3ad239c524f
xorg-x11-server-Xdmx-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: a4aab57c7c9f94119e553018c590f0e14a396dfde1b90951205498d13045f7d0
xorg-x11-server-Xephyr-1.20.11-16.el8_8.x86_64.rpm SHA-256: 312ee373ac4cefb31a9da56ba4b1cc2ef8888162f973fb2992ff40d605d0aae3
xorg-x11-server-Xephyr-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 4f2089fc05c437aab86ead33094c0af937fab4342ed3f91330678a3b62b6efa3
xorg-x11-server-Xnest-1.20.11-16.el8_8.x86_64.rpm SHA-256: 8e4a1bc6a2f7d19388b507f3c90a106726f8459789a1bc6228cda779f0ada89a
xorg-x11-server-Xnest-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: a90818ee25e11068bba6dbb0a5c5e65e3bb8eb5d58c74c975f0bdf5dbf499974
xorg-x11-server-Xorg-1.20.11-16.el8_8.x86_64.rpm SHA-256: 7fdc450be07ab4abc45b540b7476ddfed6f6c466d606ea3011138a36e9edb779
xorg-x11-server-Xorg-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 3fab554396a8f8df48caa1277d3db5a79d12874d88b1dff2c8c692a15940af58
xorg-x11-server-Xvfb-1.20.11-16.el8_8.x86_64.rpm SHA-256: 68a75165cbad2a979c2b7a6c9f5935e8b21ad5fc442f396c8ab8ca602529e59a
xorg-x11-server-Xvfb-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: c47d156378d7d479a06c4e5b9825c76589f193213ff29f271939cdbce6e5d97f
xorg-x11-server-common-1.20.11-16.el8_8.x86_64.rpm SHA-256: 0d967f2d51dddeb8a8337ebb869d42a569745bd827c56d914163e0bf4b280fda
xorg-x11-server-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 0284b528d6622c9d691a8300ea5f59a5811ae92b002f231e86af76133e098aa3
xorg-x11-server-debugsource-1.20.11-16.el8_8.x86_64.rpm SHA-256: 9924f5abc04470b998ec0a32bc1c62cc1fa65ff87dde13cc6e166025a37a8927

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
xorg-x11-server-1.20.11-16.el8_8.src.rpm SHA-256: 22e036a0f9a0ef0977743eead59cadbf68264ec872f08015729ddf3b8a826912
x86_64
xorg-x11-server-Xdmx-1.20.11-16.el8_8.x86_64.rpm SHA-256: 85736e34f010a5e01f13e8f4a691719b2e446a30bb487933e38dd3ad239c524f
xorg-x11-server-Xdmx-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: a4aab57c7c9f94119e553018c590f0e14a396dfde1b90951205498d13045f7d0
xorg-x11-server-Xephyr-1.20.11-16.el8_8.x86_64.rpm SHA-256: 312ee373ac4cefb31a9da56ba4b1cc2ef8888162f973fb2992ff40d605d0aae3
xorg-x11-server-Xephyr-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 4f2089fc05c437aab86ead33094c0af937fab4342ed3f91330678a3b62b6efa3
xorg-x11-server-Xnest-1.20.11-16.el8_8.x86_64.rpm SHA-256: 8e4a1bc6a2f7d19388b507f3c90a106726f8459789a1bc6228cda779f0ada89a
xorg-x11-server-Xnest-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: a90818ee25e11068bba6dbb0a5c5e65e3bb8eb5d58c74c975f0bdf5dbf499974
xorg-x11-server-Xorg-1.20.11-16.el8_8.x86_64.rpm SHA-256: 7fdc450be07ab4abc45b540b7476ddfed6f6c466d606ea3011138a36e9edb779
xorg-x11-server-Xorg-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 3fab554396a8f8df48caa1277d3db5a79d12874d88b1dff2c8c692a15940af58
xorg-x11-server-Xvfb-1.20.11-16.el8_8.x86_64.rpm SHA-256: 68a75165cbad2a979c2b7a6c9f5935e8b21ad5fc442f396c8ab8ca602529e59a
xorg-x11-server-Xvfb-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: c47d156378d7d479a06c4e5b9825c76589f193213ff29f271939cdbce6e5d97f
xorg-x11-server-common-1.20.11-16.el8_8.x86_64.rpm SHA-256: 0d967f2d51dddeb8a8337ebb869d42a569745bd827c56d914163e0bf4b280fda
xorg-x11-server-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 0284b528d6622c9d691a8300ea5f59a5811ae92b002f231e86af76133e098aa3
xorg-x11-server-debugsource-1.20.11-16.el8_8.x86_64.rpm SHA-256: 9924f5abc04470b998ec0a32bc1c62cc1fa65ff87dde13cc6e166025a37a8927

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
xorg-x11-server-1.20.11-16.el8_8.src.rpm SHA-256: 22e036a0f9a0ef0977743eead59cadbf68264ec872f08015729ddf3b8a826912
ppc64le
xorg-x11-server-Xdmx-1.20.11-16.el8_8.ppc64le.rpm SHA-256: ca30d4c3b9bec66036bf8a87db034fc682ffc00f5ec435d2d99a52cbaab29a84
xorg-x11-server-Xdmx-debuginfo-1.20.11-16.el8_8.ppc64le.rpm SHA-256: 2b61cb917772a0afb62cd3d32f841b359e2f3b9a95b090643c61339f3faec018
xorg-x11-server-Xephyr-1.20.11-16.el8_8.ppc64le.rpm SHA-256: bf279256c2122674ba034c5959252de9ad6e5a3ac0653d04f8fb6abdde6e3ee0
xorg-x11-server-Xephyr-debuginfo-1.20.11-16.el8_8.ppc64le.rpm SHA-256: 22f123405c1f053855f54f841e0c385f3746211f2b32cd9771ae38e08a0f915e
xorg-x11-server-Xnest-1.20.11-16.el8_8.ppc64le.rpm SHA-256: 50efb890a350a51fac482f39df350216248119b9dabd71747d39279d91cfabf1
xorg-x11-server-Xnest-debuginfo-1.20.11-16.el8_8.ppc64le.rpm SHA-256: 7576e99e2480d8d601b667ed0774e6c607138d6b1e9e989400a36c8e3686c692
xorg-x11-server-Xorg-1.20.11-16.el8_8.ppc64le.rpm SHA-256: b327767c1e1772d25be2ba4acc7c5a91c80dafdbbff056a1a5fe4df206380d26
xorg-x11-server-Xorg-debuginfo-1.20.11-16.el8_8.ppc64le.rpm SHA-256: eb0d85d2f5b297da711a4b3753cade168541b0f010a28795b397065e1446f9e1
xorg-x11-server-Xvfb-1.20.11-16.el8_8.ppc64le.rpm SHA-256: 2bff050ed5fe326860724c77c5fac0e9291a1fcfd0916075f9eb0f909109520e
xorg-x11-server-Xvfb-debuginfo-1.20.11-16.el8_8.ppc64le.rpm SHA-256: 9137f13479c7fd4294b17fc67c2b08fd2670f3f35654a2fc2e0a63703ed0dbff
xorg-x11-server-common-1.20.11-16.el8_8.ppc64le.rpm SHA-256: d974e74f5ce6cb754c97f7369b9a2e7561e06598358555197d6aa684069e6364
xorg-x11-server-debuginfo-1.20.11-16.el8_8.ppc64le.rpm SHA-256: 8f5697020636eeab7bcb1333ee9d0efd4022e55a05a464185580a1e32cf2bf99
xorg-x11-server-debugsource-1.20.11-16.el8_8.ppc64le.rpm SHA-256: f0f8bb987effc6c7df187a2567201211d0ab441b28392b6d588cac48dfc79e9d

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
xorg-x11-server-1.20.11-16.el8_8.src.rpm SHA-256: 22e036a0f9a0ef0977743eead59cadbf68264ec872f08015729ddf3b8a826912
x86_64
xorg-x11-server-Xdmx-1.20.11-16.el8_8.x86_64.rpm SHA-256: 85736e34f010a5e01f13e8f4a691719b2e446a30bb487933e38dd3ad239c524f
xorg-x11-server-Xdmx-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: a4aab57c7c9f94119e553018c590f0e14a396dfde1b90951205498d13045f7d0
xorg-x11-server-Xephyr-1.20.11-16.el8_8.x86_64.rpm SHA-256: 312ee373ac4cefb31a9da56ba4b1cc2ef8888162f973fb2992ff40d605d0aae3
xorg-x11-server-Xephyr-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 4f2089fc05c437aab86ead33094c0af937fab4342ed3f91330678a3b62b6efa3
xorg-x11-server-Xnest-1.20.11-16.el8_8.x86_64.rpm SHA-256: 8e4a1bc6a2f7d19388b507f3c90a106726f8459789a1bc6228cda779f0ada89a
xorg-x11-server-Xnest-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: a90818ee25e11068bba6dbb0a5c5e65e3bb8eb5d58c74c975f0bdf5dbf499974
xorg-x11-server-Xorg-1.20.11-16.el8_8.x86_64.rpm SHA-256: 7fdc450be07ab4abc45b540b7476ddfed6f6c466d606ea3011138a36e9edb779
xorg-x11-server-Xorg-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 3fab554396a8f8df48caa1277d3db5a79d12874d88b1dff2c8c692a15940af58
xorg-x11-server-Xvfb-1.20.11-16.el8_8.x86_64.rpm SHA-256: 68a75165cbad2a979c2b7a6c9f5935e8b21ad5fc442f396c8ab8ca602529e59a
xorg-x11-server-Xvfb-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: c47d156378d7d479a06c4e5b9825c76589f193213ff29f271939cdbce6e5d97f
xorg-x11-server-common-1.20.11-16.el8_8.x86_64.rpm SHA-256: 0d967f2d51dddeb8a8337ebb869d42a569745bd827c56d914163e0bf4b280fda
xorg-x11-server-debuginfo-1.20.11-16.el8_8.x86_64.rpm SHA-256: 0284b528d6622c9d691a8300ea5f59a5811ae92b002f231e86af76133e098aa3
xorg-x11-server-debugsource-1.20.11-16.el8_8.x86_64.rpm SHA-256: 9924f5abc04470b998ec0a32bc1c62cc1fa65ff87dde13cc6e166025a37a8927

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility