CVE-2025-26598
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 25, 2025
Updated: Mar 10, 2025
CWE ID 787
Summary
CVE-2025-26598 is a newly discovered vulnerability affecting X.Org and Xwayland. The issue lies in the GetBarrierDevice() function, which is responsible for finding a pointer device based on its ID. If a matching device ID is not found, the function will return the last element of the list instead of NULL, leading to an out-of-bounds write condition. This flaw can result in unintended memory access and, potentially, exploitation by cyber attackers. Users are advised to update their systems as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Red Hat Enterprise Linux
Affected Vendors
- Red Hat