Use-After-Free Vulnerability in X.Org and Xwayland Products
CVE-2025-26600

7.8HIGH

Key Information:

Summary

A use-after-free flaw has been identified in X.Org and Xwayland that occurs when a device is removed while still being frozen. In this scenario, events that are queued for the device persist despite the device being freed. If these events are subsequently replayed, it leads to unintended behavior and potential security risks. This issue necessitates prompt addressing to prevent exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.