Bug 2345251 (CVE-2025-26601)
Summary: | CVE-2025-26601 xorg: xwayland: Use-after-free in SyncInitTrigger() | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | security-response-team |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing a use-after-free when the alarm eventually triggers.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2349456, 2349458, 2349460 | ||
Bug Blocks: | |||
Deadline: | 2025-02-25 |
Description
OSIDB Bzimport
2025-02-12 14:23:32 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:2500 https://access.redhat.com/errata/RHSA-2025:2500 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:2502 https://access.redhat.com/errata/RHSA-2025:2502 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:2866 https://access.redhat.com/errata/RHSA-2025:2866 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:2862 https://access.redhat.com/errata/RHSA-2025:2862 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2861 https://access.redhat.com/errata/RHSA-2025:2861 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:2865 https://access.redhat.com/errata/RHSA-2025:2865 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:2873 https://access.redhat.com/errata/RHSA-2025:2873 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:2875 https://access.redhat.com/errata/RHSA-2025:2875 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:2874 https://access.redhat.com/errata/RHSA-2025:2874 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2879 https://access.redhat.com/errata/RHSA-2025:2879 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:2880 https://access.redhat.com/errata/RHSA-2025:2880 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION Via RHSA-2025:3976 https://access.redhat.com/errata/RHSA-2025:3976 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7163 https://access.redhat.com/errata/RHSA-2025:7163 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7165 https://access.redhat.com/errata/RHSA-2025:7165 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7458 https://access.redhat.com/errata/RHSA-2025:7458 |