Xorg: xwayland: heap overflow in xkbwritekeysyms()
Published Feb 25, 2025
7.8
HIGHCVSS 3.1
EPSS 0.44%
Description
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
Affected products
No data.
Configuration 3
- 7.0
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 10
xorg-x11-server-Xwayland-0:24.1.5-3.el10_0
Fixed · RHSA-2025:7458
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
tigervnc-0:1.1.0-25.el6_10
Fixed · RHSA-2025:3976
Red Hat Enterprise Linux 7 Extended Lifecycle Support
tigervnc-0:1.8.0-36.el7_9
Fixed · RHSA-2025:2861
Red Hat Enterprise Linux 7 Extended Lifecycle Support
xorg-x11-server-0:1.20.4-30.el7_9
Fixed · RHSA-2025:2879
Red Hat Enterprise Linux 8
tigervnc-0:1.13.1-15.el8_10
Fixed · RHSA-2025:2502
Red Hat Enterprise Linux 8.2 Advanced Update Support
tigervnc-0:1.9.0-15.el8_2.13
Fixed · RHSA-2025:2866
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
tigervnc-0:1.11.0-8.el8_4.12
Fixed · RHSA-2025:2865
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
tigervnc-0:1.11.0-8.el8_4.12
Fixed · RHSA-2025:2865
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
tigervnc-0:1.11.0-8.el8_4.12
Fixed · RHSA-2025:2865
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
tigervnc-0:1.12.0-6.el8_6.13
Fixed · RHSA-2025:2880
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
tigervnc-0:1.12.0-6.el8_6.13
Fixed · RHSA-2025:2880
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
tigervnc-0:1.12.0-6.el8_6.13
Fixed · RHSA-2025:2880
Red Hat Enterprise Linux 8.8 Extended Update Support
tigervnc-0:1.12.0-15.el8_8.12
Fixed · RHSA-2025:2862
Red Hat Enterprise Linux 9
tigervnc-0:1.14.1-1.el9_5.1
Fixed · RHSA-2025:2500
Red Hat Enterprise Linux 9
xorg-x11-server-0:1.20.11-28.el9_6
Fixed · RHSA-2025:7163
Red Hat Enterprise Linux 9
xorg-x11-server-Xwayland-0:23.2.7-3.el9_6
Fixed · RHSA-2025:7165
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
tigervnc-0:1.11.0-22.el9_0.13
Fixed · RHSA-2025:2873
Red Hat Enterprise Linux 9.2 Extended Update Support
tigervnc-0:1.12.0-14.el9_2.10
Fixed · RHSA-2025:2874
Red Hat Enterprise Linux 9.4 Extended Update Support
tigervnc-0:1.13.1-8.el9_4.5
Fixed · RHSA-2025:2875
Red Hat Enterprise Linux 6
xorg-x11-server
Out of support scope
Red Hat Enterprise Linux 8
xorg-x11-server
Not affected
Red Hat Enterprise Linux 8
xorg-x11-server-Xwayland
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | xorg-x11-server-Xwayland-0:24.1.5-3.el10_0 | Fixed | RHSA-2025:7458 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | tigervnc-0:1.1.0-25.el6_10 | Fixed | RHSA-2025:3976 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | tigervnc-0:1.8.0-36.el7_9 | Fixed | RHSA-2025:2861 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | xorg-x11-server-0:1.20.4-30.el7_9 | Fixed | RHSA-2025:2879 |
| Red Hat Enterprise Linux 8 | tigervnc-0:1.13.1-15.el8_10 | Fixed | RHSA-2025:2502 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | tigervnc-0:1.9.0-15.el8_2.13 | Fixed | RHSA-2025:2866 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | tigervnc-0:1.11.0-8.el8_4.12 | Fixed | RHSA-2025:2865 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | tigervnc-0:1.11.0-8.el8_4.12 | Fixed | RHSA-2025:2865 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | tigervnc-0:1.11.0-8.el8_4.12 | Fixed | RHSA-2025:2865 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | tigervnc-0:1.12.0-6.el8_6.13 | Fixed | RHSA-2025:2880 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | tigervnc-0:1.12.0-6.el8_6.13 | Fixed | RHSA-2025:2880 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | tigervnc-0:1.12.0-6.el8_6.13 | Fixed | RHSA-2025:2880 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | tigervnc-0:1.12.0-15.el8_8.12 | Fixed | RHSA-2025:2862 |
| Red Hat Enterprise Linux 9 | tigervnc-0:1.14.1-1.el9_5.1 | Fixed | RHSA-2025:2500 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-0:1.20.11-28.el9_6 | Fixed | RHSA-2025:7163 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland-0:23.2.7-3.el9_6 | Fixed | RHSA-2025:7165 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | tigervnc-0:1.11.0-22.el9_0.13 | Fixed | RHSA-2025:2873 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | tigervnc-0:1.12.0-14.el9_2.10 | Fixed | RHSA-2025:2874 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | tigervnc-0:1.13.1-8.el9_4.5 | Fixed | RHSA-2025:2875 |
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | xorg-x11-server | Not affected | n/a |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore, Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity and are not affected by this bug.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (20)
- https://access.redhat.com/errata/RHSA-2025:2500 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2502 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2861 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2862 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2865 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2866 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2873 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2874 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2875 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2879 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:2880 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:3976 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:7163 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:7165 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:7458 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-26596 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2345256 issue-trackingx_refsource_REDHATIssue Tracking
- https://lists.debian.org/debian-lts-announce/2025/02/msg00036.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-26596
- https://www.cve.org/CVERecord?id=CVE-2025-26596
Change history (0)
No recorded changes yet.