Bug 2345257 (CVE-2025-26595)
Summary: | CVE-2025-26595 Xorg: xwayland: Buffer overflow in XkbVModMaskText() | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | security-response-team |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2349373, 2349374, 2349375 | ||
Bug Blocks: | |||
Deadline: | 2025-02-25 |
Description
OSIDB Bzimport
2025-02-12 14:23:56 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:2500 https://access.redhat.com/errata/RHSA-2025:2500 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:2502 https://access.redhat.com/errata/RHSA-2025:2502 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:2866 https://access.redhat.com/errata/RHSA-2025:2866 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:2862 https://access.redhat.com/errata/RHSA-2025:2862 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2861 https://access.redhat.com/errata/RHSA-2025:2861 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:2865 https://access.redhat.com/errata/RHSA-2025:2865 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:2873 https://access.redhat.com/errata/RHSA-2025:2873 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:2875 https://access.redhat.com/errata/RHSA-2025:2875 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:2874 https://access.redhat.com/errata/RHSA-2025:2874 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2879 https://access.redhat.com/errata/RHSA-2025:2879 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:2880 https://access.redhat.com/errata/RHSA-2025:2880 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION Via RHSA-2025:3976 https://access.redhat.com/errata/RHSA-2025:3976 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7163 https://access.redhat.com/errata/RHSA-2025:7163 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7165 https://access.redhat.com/errata/RHSA-2025:7165 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7458 https://access.redhat.com/errata/RHSA-2025:7458 |