关键漏洞信息 漏洞概述 类型/严重性: 重要 主题: TigerVNC的安全更新,修复了多个安全漏洞。 影响的产品 Red Hat Enterprise Linux Server - Extended Life Cycle Support 7.x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7.s390x Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7.ppc64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7.ppc64le 安全修复 CVE-2025-49175: xorg-x11-server-Xwayland: xorg-x11-server: tigerVNC: Out-of-Bounds Read in X Rendering Extension Animated Cursors CVE-2025-49176: xorg-x11-server-Xwayland: xorg-x11-server: tigerVNC: Integer Overflow in Big Requests Extension CVE-2025-49178: xorg-x11-server-Xwayland: xorg-x11-server: tigerVNC: Unprocessed Client Request Due to Bytes to Ignore CVE-2025-49179: xorg-x11-server-Xwayland: xorg-x11-server: tigerVNC: Integer overflow in X Record extension CVE-2025-49180: xorg-x11-server-Xwayland: xorg-x11-server: tigerVNC: Integer Overflow in X Resize, Rotate and Reflect (RandR) Extension 解决方案 参考链接: https://access.redhat.com/articles/11258 CVE编号 CVE-2025-49175 CVE-2025-49176 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180 参考资料 https://access.redhat.com/security/updates/classification/#important