Bug 2345254 (CVE-2025-26598)
Summary: | CVE-2025-26598 xorg: xwayland: Out-of-bounds write in CreatePointerBarrierClient() | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | security-response-team |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2349364, 2349365, 2349366 | ||
Bug Blocks: | |||
Deadline: | 2025-02-25 |
Description
OSIDB Bzimport
2025-02-12 14:23:42 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:2500 https://access.redhat.com/errata/RHSA-2025:2500 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:2502 https://access.redhat.com/errata/RHSA-2025:2502 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:2866 https://access.redhat.com/errata/RHSA-2025:2866 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:2862 https://access.redhat.com/errata/RHSA-2025:2862 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2861 https://access.redhat.com/errata/RHSA-2025:2861 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:2865 https://access.redhat.com/errata/RHSA-2025:2865 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:2873 https://access.redhat.com/errata/RHSA-2025:2873 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:2875 https://access.redhat.com/errata/RHSA-2025:2875 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:2874 https://access.redhat.com/errata/RHSA-2025:2874 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2879 https://access.redhat.com/errata/RHSA-2025:2879 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:2880 https://access.redhat.com/errata/RHSA-2025:2880 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION Via RHSA-2025:3976 https://access.redhat.com/errata/RHSA-2025:3976 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7163 https://access.redhat.com/errata/RHSA-2025:7163 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7165 https://access.redhat.com/errata/RHSA-2025:7165 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7458 https://access.redhat.com/errata/RHSA-2025:7458 |