Description
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux9.0 – 9.0
- TigerVNC / TigerVNC
- X.Org / X server21.1.16
- X.Org / xwayland24.1.6
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2500
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2502
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2861
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2862
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2865
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2866
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2873
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2874
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2875
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2879
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:2880
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:3976
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:7163
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:7165
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2025:7458
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2025-26597
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2345255
Updated 31m ago · 8 sources