CVE-2025-26595: Red Hat Enterprise Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.

Affected products

  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Tigervnc Tigervnc: affected versions not specified
  • X.org X Server: before 21.1.16 (fixed in 21.1.16)
  • X.org Xwayland: before 24.1.6 (fixed in 24.1.6)

Published 2025-02-25. Last modified 2026-06-29.