Required CVE Record Information
Description
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
7.8 | HIGH | 3.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Product Status
Learn moreVersions 2 Total
Default Status: unaffected
affected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 0 Total
Default Status: All versions are affected
Versions 0 Total
Default Status: All versions are unknown
Versions 0 Total
Default Status: All versions are unaffected
Versions 0 Total
Default Status: All versions are unaffected
Versions 0 Total
Default Status: All versions are affected
Versions 0 Total
Default Status: All versions are affected
References 13 Total
- access.redhat.com: RHSA-2025:2500 vendor-advisory
- access.redhat.com: RHSA-2025:2502 vendor-advisory
- access.redhat.com: RHSA-2025:2861 vendor-advisory
- access.redhat.com: RHSA-2025:2862 vendor-advisory
- access.redhat.com: RHSA-2025:2865 vendor-advisory
- access.redhat.com: RHSA-2025:2866 vendor-advisory
- access.redhat.com: RHSA-2025:2873 vendor-advisory
- access.redhat.com: RHSA-2025:2874 vendor-advisory
- access.redhat.com: RHSA-2025:2875 vendor-advisory
- access.redhat.com: RHSA-2025:2879 vendor-advisory
- access.redhat.com: RHSA-2025:2880 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26598 vdb-entry
- bugzilla.redhat.com: RHBZ#2345254 issue-tracking