Vulnerabilities > CVE-2025-26595 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
tigervnc
x-org
redhat
CWE-787

Summary

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.

Vulnerable Configurations

Part Description Count
Application
Tigervnc
1
Application
X.Org
302
OS
Redhat
3

Common Weakness Enumeration (CWE)