CVE-2025-26594
25.02.2025, 16:15
A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.Enginsight
Vendor | Product | Version |
---|---|---|
tigervnc | tigervnc | - |
x.org | x_server | - |
x.org | xwayland | - |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
xorg |
| ||||||||||||
xorg-hwe-16.04 |
| ||||||||||||
xorg-hwe-18.04 |
| ||||||||||||
xorg-server |
| ||||||||||||
xorg-server-hwe-16.04 |
| ||||||||||||
xorg-server-hwe-18.04 |
| ||||||||||||
xwayland |
|
Common Weakness Enumeration
Vulnerability Media Exposure
References