The code in XkbVModMaskText() allocates a fixed sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code however fails to check the bounds of the buffer correctly and would copy the data regardless of the size, which may lead to a buffer overflow.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:2500 https://access.redhat.com/errata/RHSA-2025:2500
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:2502 https://access.redhat.com/errata/RHSA-2025:2502
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:2866 https://access.redhat.com/errata/RHSA-2025:2866
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:2862 https://access.redhat.com/errata/RHSA-2025:2862
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2861 https://access.redhat.com/errata/RHSA-2025:2861
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:2865 https://access.redhat.com/errata/RHSA-2025:2865
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:2873 https://access.redhat.com/errata/RHSA-2025:2873
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:2875 https://access.redhat.com/errata/RHSA-2025:2875
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:2874 https://access.redhat.com/errata/RHSA-2025:2874
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2879 https://access.redhat.com/errata/RHSA-2025:2879
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:2880 https://access.redhat.com/errata/RHSA-2025:2880
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION Via RHSA-2025:3976 https://access.redhat.com/errata/RHSA-2025:3976
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7163 https://access.redhat.com/errata/RHSA-2025:7163
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7165 https://access.redhat.com/errata/RHSA-2025:7165
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7458 https://access.redhat.com/errata/RHSA-2025:7458