Heap Overflow Vulnerability in X.Org and Xwayland
CVE-2025-26596

7.8HIGH

Key Information:

Summary

A heap overflow flaw has been identified in X.Org and Xwayland due to improper handling of length calculations in the XkbSizeKeySyms() function. This vulnerability arises when the calculated size does not match the information written in the XkbWriteKeySyms() function, potentially resulting in a heap-based buffer overflow. Such an oversight may permit malicious actors to manipulate memory allocation, leading to unauthorized access or execution of arbitrary code within the affected systems.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.