CVE-2025-26596
Xorg: xwayland: heap overflow in xkbwritekeysyms()
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the XkbSizeKeySyms function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-02-12 CVE Reserved
- 2025-02-25 CVE Published
- 2025-04-14 CVE Updated
- 2025-05-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (13)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2025-26596 | 2025-02-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2345256 | 2025-02-25 | |
https://access.redhat.com/errata/RHSA-2025:2500 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2502 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2861 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2862 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2865 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2866 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2873 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2874 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2875 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2879 | 2025-04-14 | |
https://access.redhat.com/errata/RHSA-2025:2880 | 2025-04-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Red Hat Search vendor "Red Hat" | Enterprise Linux Search vendor "Red Hat" for product "Enterprise Linux" | * | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | * | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | * | - |
Affected
|