CVE-2025-26597
25.02.2025, 16:15
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size.Enginsight
Vendor | Product | Version |
---|---|---|
tigervnc | tigervnc | - |
x.org | x_server | 𝑥 < 21.1.16 |
x.org | xwayland | 𝑥 < 24.1.6 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
xorg |
| ||||||||||||||||
xorg-hwe-16.04 |
| ||||||||||||||||
xorg-hwe-18.04 |
| ||||||||||||||||
xorg-server |
| ||||||||||||||||
xorg-server-hwe-16.04 |
| ||||||||||||||||
xorg-server-hwe-18.04 |
| ||||||||||||||||
xwayland |
|
Common Weakness Enumeration
References