yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-49176
Component Overview
Vulnerability Overview
Name
CVE-2025-49176
Source
NVD (
link
)
Debian (
link
)
Description
A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
CWEs
CWE-190
Published Date
Jun 17, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
xwayland
Patched
Vulnerability Ratings
#
7.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
xwayland
buildroot
2025.02.x
24.1.12
Not Affected
xwayland
buildroot
master
24.1.12
Not Affected
xwayland
yocto
kirkstone
22.1.8
Patched
xwayland
yocto
master
24.1.12
Not Affected
Resolved with patches
#
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
os: Check for integer overflow on BigRequest length
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-49176
2
os: Do not overflow the integer size with BigRequest
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-49176
xwayland (yocto:scarthgap)
#
Title
Author
Resolve
1
os: Check for integer overflow on BigRequest length
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-49176
2
os: Do not overflow the integer size with BigRequest
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-49176