CVE-2025-26595

Updated: 2026-02-27 02:44:48.262997

Description:

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU xorg-x11-server-Xwayland 21.1.3 7.8 HIGH Released CLSA-2025:1764027165 2025-11-25 02:26:40
AlmaLinux 9.2 ESU tigervnc 1.12.0 7.8 HIGH Released CLSA-2025:1742920518 2025-03-26 03:24:42
CentOS 7 ELS xorg-x11-server 1.20.4 7.8 HIGH Released CLSA-2025:1756409662 2025-09-11 21:32:16
Oracle Linux 7 ELS xorg-x11-server 1.20.4 7.8 HIGH Released CLSA-2025:1760646154 2025-10-17 05:39:54
Oracle Linux 7 ELS tigervnc 1.8.0 7.8 HIGH Released CLSA-2025:1760646561 2025-10-17 05:40:31
RHEL 7 ELS xorg-x11-server 1.20.4 7.8 HIGH Released CLSA-2025:1756408410 2025-08-28 22:56:01
TuxCare 9.6 ESU tigervnc 1.14.1 7.8 HIGH Already Fixed 2025-12-02 17:04:34
TuxCare 9.6 ESU xorg-x11-server-Xwayland 23.2.7 7.8 HIGH Already Fixed 2025-12-02 17:04:25