RHSA-2025:7165MediumCVSS 7.8
Red Hat Security Advisory: xorg-x11-server-Xwayland security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2024-9632 — xorg-x11-server: tigervnc: heap-based buffer overflow privilege escalation vulnerability CVE-2025-26594 — X.Org: Xwayland: Use-after-free of the root cursor CVE-2025-26595 — Xorg: xwayland: Buffer overflow in XkbVModMaskText() CVE-2025-26596 — xorg: xwayland: Heap overflow in XkbWriteKeySyms() CVE-2025-26597 — xorg: xwayland: Buffer overflow in XkbChangeTypesOfKey() CVE-2025-26598 — xorg: xwayland: Out-of-bounds write in CreatePointerBarrierClient() CVE-2025-26599 — xorg: xwayland: Use of uninitialized pointer in compRedirectWindow() CVE-2025-26600 — xorg: xwayland: Use-after-free in PlayReleasedEvents() CVE-2025-26601 — xorg: xwayland: Use-after-free in SyncInitTrigger()
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2025:7165
- externalhttps://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.6_release_notes/index
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317233
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345248
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345251
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345253
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345254
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345255
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345256
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345257
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_7165.json