View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2025-49176 severity important: SUSE including 319 source package names (21.1-46.1:xorg-x11-server-21.1.11-150600.5.12.1, 21.1-46.1:xorg-x11-server-Xvfb-21.1.11-150600.5.12.1, …), 405 product×package rows across 56 product lines (Container suse/kiosk/xorg, Image SLES15-SP4-SAP, … (56 product lines)): Known Affected 231, Fixed 174.
A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.