CVE-2025-26598: Red Hat Enterprise Linux
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.
Affected products
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Tigervnc Tigervnc: affected versions not specified
- X.org X Server: before 21.1.16 (fixed in 21.1.16)
- X.org Xwayland: before 24.1.6 (fixed in 24.1.6)
Published 2025-02-25. Last modified 2026-06-29.