- What: A resource exhaustion vulnerability exists in fvwm3 on Fedora 42.
- Impact: A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
- Affected: fvwm3 on Fedora 42.
- CVE: CVE-2025-65637
- Patch: Install the update from the vendor's website.
Main Vulnerability Database SB2026021102 SB2026021102 - Fedora 42 update for fvwm3 Published: February 11, 2026 Security Bulletin ID SB2026021102 Severity Medium Patch available YES Number of vulnerabilities 1 Exploitation vector Remote access Highest impact Denial of service Breakdown by Severity Low Medium High Critical Description This security bulletin contains information about 1 security vulnerability. 1) Resource exhaustion (CVE-ID: CVE-2025-65637) The vulnerability allows a remote attacker to perform a denial of service (DoS) attack. The vulnerability exists due to application does not properly control consumption of internal resources when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack. Remediation Install update from vendor's website. References https://bodhi.fedoraproject.org/updates/FEDORA-2026-439af2cc95