Name
CVE-2025-26595
Description
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2025:2500Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2502Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2861Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2862Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2865Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2866Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2873Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2874Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2875Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2879Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2880Third Party Advisory
https://access.redhat.com/security/cve/CVE-2025-26595Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2345257Issue Tracking
Analysis#
Vulnerability Ratings#
7.8
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
xserver-xorg (yocto:kirkstone)
#
Title
Author
Resolve
1
xkb: Fix buffer overflow in XkbVModMaskText()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26595
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
xkb: Fix buffer overflow in XkbVModMaskText()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26595
xwayland (yocto:scarthgap)
#
Title
Author
Resolve
1
xkb: Fix buffer overflow in XkbVModMaskText()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26595