CVE-2025-26599
25.02.2025, 16:15
An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized pointer later.Enginsight
| Vendor | Product | Version |
|---|---|---|
| tigervnc | tigervnc | - |
| x.org | x_server | 𝑥 < 21.1.16 |
| x.org | xwayland | 𝑥 < 24.1.6 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-server |
| ||||||||||||||||
| xwayland |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg |
| ||||||||||||||||||
| xorg-server |
| ||||||||||||||||||
| xwayland |
| ||||||||||||||||||
| xorg-server-hwe-16.04 |
| ||||||||||||||||||
| xorg-server-hwe-18.04 |
| ||||||||||||||||||
| xorg-hwe-16.04 |
| ||||||||||||||||||
| xorg-hwe-18.04 |
|
Common Weakness Enumeration
References