CVE-2025-26596
HIGHTigervnc < 21.1.16 - Out-of-Bounds Write
Title source: ruleDescription
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
References (17)
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
18.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-787
Status
published
Affected Products (6)
x.org/x_server
< 21.1.16
tigervnc/tigervnc
x.org/xwayland
< 24.1.6
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux
Timeline
Published
Feb 25, 2025
Tracked Since
Feb 18, 2026