CVE-2025-26598

An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
tigervnctigervnc
-
x.orgx_server
-
x.orgxwayland
-
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xorg-server
bullseye
vulnerable
bookworm
2:21.1.7-3+deb12u9
ignored
bullseye (security)
2:1.20.11-1+deb11u15
fixed
bookworm (security)
2:21.1.7-3+deb12u9
fixed
sid
2:21.1.16-1
fixed
trixie
2:21.1.16-1
fixed
xwayland
bookworm
ignored
sid
2:24.1.6-1
fixed
trixie
2:24.1.6-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xorg
oracular
not-affected
noble
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
xorg-hwe-16.04
oracular
dne
noble
dne
jammy
dne
focal
dne
xenial
not-affected
xorg-hwe-18.04
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
not-affected
xorg-server
oracular
Fixed 2:21.1.13-2ubuntu1.2
released
noble
Fixed 2:21.1.12-1ubuntu1.2
released
jammy
Fixed 2:21.1.4-2ubuntu1.7~22.04.13
released
focal
Fixed 2:1.20.13-1ubuntu1~20.04.19
released
bionic
Fixed 2:1.19.6-1ubuntu4.15+esm12
released
xenial
Fixed 2:1.18.4-0ubuntu0.12+esm17
released
xorg-server-hwe-16.04
oracular
dne
noble
dne
jammy
dne
focal
dne
xenial
Fixed 2:1.19.6-1ubuntu4.1~16.04.6+esm9
released
xorg-server-hwe-18.04
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
Fixed 2:1.20.8-2ubuntu2.2~18.04.11+esm4
released
xwayland
oracular
Fixed 2:24.1.2-1ubuntu0.4
released
noble
Fixed 2:23.2.6-1ubuntu0.4
released
jammy
Fixed 2:22.1.1-1ubuntu0.17
released
focal
dne