Name
CVE-2025-26601
Description
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing a use-after-free when the alarm eventually triggers.
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2025:2500Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2502Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2861Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2862Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2865Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2866Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2873Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2874Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2875Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2879Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:2880Third Party Advisory
https://access.redhat.com/security/cve/CVE-2025-26601Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2345251Issue Tracking
Analysis#
Vulnerability Ratings#
7.8
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
xserver-xorg (yocto:kirkstone)
#
Title
Author
Resolve
1
sync: Do not fail SyncAddTriggerToSyncObject()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
2
sync: Check values before applying changes
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
3
sync: Do not let sync objects uninitialized
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
4
sync: Apply changes last in SyncChangeAlarmAttributes()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
sync: Do not fail SyncAddTriggerToSyncObject()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
2
sync: Check values before applying changes
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
3
sync: Do not let sync objects uninitialized
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
4
sync: Apply changes last in SyncChangeAlarmAttributes()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
xwayland (yocto:scarthgap)
#
Title
Author
Resolve
1
sync: Do not fail SyncAddTriggerToSyncObject()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
2
sync: Check values before applying changes
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
3
sync: Do not let sync objects uninitialized
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601
4
sync: Apply changes last in SyncChangeAlarmAttributes()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-26601