First published: Wed Feb 12 2025(Updated: )
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/xorg-server | <=2:1.20.11-1+deb11u13<=2:21.1.7-3+deb12u8<=2:21.1.15-3 | 2:1.20.11-1+deb11u15 2:21.1.7-3+deb12u9 2:21.1.16-1 |
debian/xwayland | <=2:22.1.9-1<=2:24.1.5-1 | 2:24.1.6-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26596 is classified as a high severity vulnerability due to the potential for a heap-based buffer overflow.
CVE-2025-26596 affects the xorg-server and xwayland packages on Debian systems.
To fix CVE-2025-26596, update the affected xorg-server and xwayland packages to their latest versions as recommended by your distribution.
CVE-2025-26596 could be exploited through local code execution leading to potential unauthorized access or system compromise.
CVE-2025-26596 was last updated on 25 February 2025.