CVE-2025-26596: Xorg: xwayland: heap overflow in xkbwritekeysyms()
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
Other sources
The computation of the length in XkbSizeKeySyms() differs from what is actually written in XkbWriteKeySyms(), which may lead to a heap based buffer overflow.
— Red Hat
Xorg: xwayland: heap overflow in xkbwritekeysyms()
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xorg-serverto a version that resolves this vulnerability.Fixed in 2:1.20.11-1+deb11u15Fixed in 2:21.1.7-3+deb12u9Fixed in 2:21.1.16-1 - Upgrade
Upgrade
debian/xwaylandto a version that resolves this vulnerability.Fixed in 2:24.1.6-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.1.6-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.20.10-15
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26596?
CVE-2025-26596 is classified as a high severity vulnerability due to the potential for a heap-based buffer overflow.
What systems are affected by CVE-2025-26596?
CVE-2025-26596 affects the xorg-server and xwayland packages on Debian systems.
How do I fix CVE-2025-26596?
To fix CVE-2025-26596, update the affected xorg-server and xwayland packages to their latest versions as recommended by your distribution.
What kind of attack can exploit CVE-2025-26596?
CVE-2025-26596 could be exploited through local code execution leading to potential unauthorized access or system compromise.
When was CVE-2025-26596 last updated?
CVE-2025-26596 was last updated on 25 February 2025.