RHSA-2025:2879: Important: xorg-x11-server security update
Important: xorg-x11-server security update
Other sources
X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.Security Fix(es): X.Org: Xwayland: Use-after-free of the root cursor (CVE-2025-26594) xorg: xwayland: Use-after-free in SyncInitTrigger() (CVE-2025-26601) xorg: xwayland: Use-after-free in PlayReleasedEvents() (CVE-2025-26600) xorg: xwayland: Use of uninitialized pointer in compRedirectWindow() (CVE-2025-26599) xorg: xwayland: Out-of-bounds write in CreatePointerBarrierClient() (CVE-2025-26598) xorg: xwayland: Buffer overflow in XkbChangeTypesOfKey() (CVE-2025-26597) xorg: xwayland: Heap overflow in XkbWriteKeySyms() (CVE-2025-26596) Xorg: xwayland: Buffer overflow in XkbVModMaskText() (CVE-2025-26595) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:2879?
The severity of RHSA-2025:2879 is classified as moderate due to the use-after-free vulnerability in Xwayland.
How do I fix RHSA-2025:2879?
To fix RHSA-2025:2879, update the xorg-x11-server and related packages to version 1.20.4-30.el7_9 or later.
What software is affected by RHSA-2025:2879?
RHSA-2025:2879 affects the xorg-x11-server, xorg-x11-server-common, and related packages on Red Hat platforms.
Is there a workaround for RHSA-2025:2879?
No specific workarounds are recommended for RHSA-2025:2879; updating the software is the advised action.
When was RHSA-2025:2879 released?
RHSA-2025:2879 was released to address the vulnerabilities in March 2025.