CVE-2025-26598
HIGHTigerVNC - Out-of-bounds Write in GetBarrierDevice Function
Title source: llmDescription
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.
References (18)
Core 18
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2025:3976
https://access.redhat.com/errata/RHSA-2025:3976
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2500
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2502
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2861
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2862
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2865
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2866
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2873
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2874
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2875
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2879
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:2880
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:7163
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:7165
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:7458
Third Party Advisory vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2025-26598
Issue Tracking issue-tracking
x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2345254
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
11.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (27)
Red Hat/Red Hat Enterprise Linux 10
0:24.1.5-3.el10_0
Red Hat/Red Hat Enterprise Linux 6
Red Hat/Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
0:1.1.0-25.el6_10
Red Hat/Red Hat Enterprise Linux 7 Extended Lifecycle Support
0:1.20.4-30.el7_9
Red Hat/Red Hat Enterprise Linux 7 Extended Lifecycle Support
0:1.8.0-36.el7_9
Red Hat/Red Hat Enterprise Linux 8
Red Hat/Red Hat Enterprise Linux 8
0:1.13.1-15.el8_10
Red Hat/Red Hat Enterprise Linux 8.2 Advanced Update Support
0:1.9.0-15.el8_2.13
Red Hat/Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
0:1.11.0-8.el8_4.12
Red Hat/Red Hat Enterprise Linux 8.4 Telecommunications Update Service
0:1.11.0-8.el8_4.12
... and 17 more
Published
Feb 25, 2025
Tracked Since
Feb 18, 2026