CVE-2025-26595

Source
https://cve.org/CVERecord?id=CVE-2025-26595
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-26595.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-26595
Downstream
Related
Published
2025-02-25T15:54:06.708Z
Modified
2026-05-15T11:53:36.366054995Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Xorg: xwayland: buffer overflow in xkbvmodmasktext()
Details

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.

Database specific
{
    "cwe_ids": [
        "CWE-121"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/26xxx/CVE-2025-26595.json",
    "cna_assigner": "redhat"
}
References

Affected packages