Wind River Support Network

HomeDefectsLIN1021-13548
Fixed

LIN1021-13548 : Security Advisory - xserver-xorg - CVE-2025-26598

Created: Feb 25, 2025    Updated: May 25, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.

CREATE(Triage):(User=admin) CVE-2025-26598 (https://nvd.nist.gov/vuln/detail/CVE-2025-26598)

CVEs


Live chat
Online