Wind River Support Network

HomeDefectsLIN1021-13545
Fixed

LIN1021-13545 : Security Advisory - xserver-xorg - CVE-2025-26595

Created: Feb 25, 2025    Updated: May 25, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.

CREATE(Triage):(User=admin) CVE-2025-26595 (https://nvd.nist.gov/vuln/detail/CVE-2025-26595)

CVEs


Live chat
Online