CVE-2025-26598

high
Published 2025-03-10 · Modified 2025-03-10
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
8.0

Description

RHSA-2025:2502: tigervnc security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description xorg: xwayland: Out-of-bounds write in CreatePointerBarrierClient() Red Hat statement Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore, Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity and are not affected by this bug. CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Errata / fixed releases…

Description

xorg: xwayland: Out-of-bounds write in CreatePointerBarrierClient()

Red Hat statement

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore, Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity and are not affected by this bug.

CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10xorg-x11-server-Xwayland-0:24.1.5-3.el10_0RHSA-2025:74582025-05-13T00:00:00Z
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervnc-0:1.1.0-25.el6_10RHSA-2025:39762025-04-17T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supporttigervnc-0:1.8.0-36.el7_9RHSA-2025:28612025-03-17T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-server-0:1.20.4-30.el7_9RHSA-2025:28792025-03-17T00:00:00Z
Red Hat Enterprise Linux 8tigervnc-0:1.13.1-15.el8_10RHSA-2025:25022025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supporttigervnc-0:1.9.0-15.el8_2.13RHSA-2025:28662025-03-17T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supporttigervnc-0:1.11.0-8.el8_4.12RHSA-2025:28652025-03-17T00:00:00Z
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicetigervnc-0:1.11.0-8.el8_4.12RHSA-2025:28652025-03-17T00:00:00Z
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionstigervnc-0:1.11.0-8.el8_4.12RHSA-2025:28652025-03-17T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supporttigervnc-0:1.12.0-6.el8_6.13RHSA-2025:28802025-03-17T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicetigervnc-0:1.12.0-6.el8_6.13RHSA-2025:28802025-03-17T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionstigervnc-0:1.12.0-6.el8_6.13RHSA-2025:28802025-03-17T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supporttigervnc-0:1.12.0-15.el8_8.12RHSA-2025:28622025-03-17T00:00:00Z
Red Hat Enterprise Linux 9tigervnc-0:1.14.1-1.el9_5.1RHSA-2025:25002025-03-10T00:00:00Z
Red Hat Enterprise Linux 9xorg-x11-server-0:1.20.11-28.el9_6RHSA-2025:71632025-05-13T00:00:00Z
Red Hat Enterprise Linux 9xorg-x11-server-Xwayland-0:23.2.7-3.el9_6RHSA-2025:71652025-05-13T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionstigervnc-0:1.11.0-22.el9_0.13RHSA-2025:28732025-03-17T00:00:00Z
Red Hat Enterprise Linux 9.2 Extended Update Supporttigervnc-0:1.12.0-14.el9_2.10RHSA-2025:28742025-03-17T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supporttigervnc-0:1.13.1-8.el9_4.5RHSA-2025:28752025-03-17T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 8xorg-x11-serverNot affected
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandNot affected

Apply commands

bash fix
Apply RHSA-2025:7458 for Red Hat Enterprise Linux 10
yum update -y xorg-x11-server-Xwayland
# or:
dnf upgrade -y xorg-x11-server-Xwayland

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
rockylinux rocky9fixed
debian debianbookwormfixed2:21.1.7-3+deb12u9
debian debianbullseyefixed2:1.20.11-1+deb11u15
debian debianforkyfixed2:21.1.16-1
debian debiansidfixed2:21.1.16-1
debian debiantrixiefixed2:21.1.16-1
almalinux almalinux9fixedtigervnc-icons-1.14.1-1.el9_5.1.noarch.rpm
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.