Vulnerability CVE-2025-26594: Information

Description

A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.

Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: Feb. 25, 2025
Modified: April 6, 2026
Error type identifier: CWE-416

Fixed packages

References to Advisories, Solutions, and Tools

    1. cpe:2.3:a:tigervnc:tigervnc:-:*:*:*:*:*:*:*

      cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*
      End excluding
      21.1.16

      cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:*
      End excluding
      24.1.6

      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*