CVE-2025-26600: Xorg: xwayland: use-after-free in playreleasedevents()
A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.
Other sources
When a device is removed while still frozen, the events queued for that device remain while the device itself is freed and replaying the events will cause a use after free.
— Red Hat
Xorg: xwayland: use-after-free in playreleasedevents()
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xorg-serverto a version that resolves this vulnerability.Fixed in 2:1.20.11-1+deb11u15Fixed in 2:21.1.7-3+deb12u9Fixed in 2:21.1.16-1 - Upgrade
Upgrade
debian/xwaylandto a version that resolves this vulnerability.Fixed in 2:24.1.6-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.20.10-15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.1.6-1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26600?
CVE-2025-26600 is classified as a high-severity vulnerability due to the potential for use-after-free exploitation.
How do I fix CVE-2025-26600?
To remediate CVE-2025-26600, update the affected X.Org and Xwayland packages to their latest versions as specified by your distribution.
What are the affected versions for CVE-2025-26600?
CVE-2025-26600 affects specific versions of X.Org Xwayland, including versions prior to the latest security patches.
What software is impacted by CVE-2025-26600?
CVE-2025-26600 specifically impacts X.Org and Xwayland components used on various Linux distributions.
Is there a workaround for CVE-2025-26600?
Currently, there are no known workarounds for CVE-2025-26600; updates are recommended to mitigate the vulnerability.