CVE-2025-26600
HIGHTigervnc < 21.1.16 - Use After Free
Title source: ruleDescription
A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.
References (18)
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
18.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-416
Status
published
Affected Products (6)
tigervnc/tigervnc
x.org/x_server
< 21.1.16
x.org/xwayland
< 24.1.6
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux
Timeline
Published
Feb 25, 2025
Tracked Since
Feb 18, 2026