关键漏洞信息 概述 公告编号: RHSA-2025:10355 发布日期: 2025-07-07 更新日期: 2025-07-07 类型/严重性: 安全公告 - 重要 主题 产品: Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions 和 Red Hat Enterprise Linux 8.6 Telecommunications Update Service 影响: 重要安全更新,涉及多个CVE漏洞 描述 组件: tigervnc 漏洞详情: - CVE-2025-49175: Out-of-Bounds Read in X Rendering Extension Animated Cursors - CVE-2025-49176: Integer Overflow in Big Requests Extension - CVE-2025-49178: Unprocessed Client Request Due to Bytes to Ignore - CVE-2025-49179: Integer overflow in X Record extension - CVE-2025-49180: Integer Overflow in X Resize, Rotate and Reflect (RandR) Extension 影响的产品 Red Hat Enterprise Linux Server - TUS 8.6 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64 解决方案 参考链接: https://access.redhat.com/articles/11258 固定的CVEs CVE-2025-49175 CVE-2025-49176 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180 参考资料 https://access.redhat.com/security/updates/classification/#important