CVE-2025-26597High· 7.8▾ TwilightA buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zer…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size.
tigervncx_server < 21.1.16xwayland < 24.1.6enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0Upgrade past the affected range:
x_server 21.1.16xwayland 24.1.6Connected by shared product, vendor, weakness, or advisory.
CVE-2025-26601High· 7.8A use-after-free flaw was found in X.Org and Xwayland
CVE-2025-26600High· 7.8A use-after-free flaw was found in X.Org and Xwayland
CVE-2025-26599High· 7.8An access to an uninitialized pointer flaw was found in X.Org and Xwayland
CVE-2025-26598High· 7.8An out-of-bounds write flaw was found in X.Org and Xwayland
CVE-2025-26596High· 7.8A heap overflow flaw was found in X.Org and Xwayland
CVE-2025-26595High· 7.8A buffer overflow flaw was found in X.Org and Xwayland