CVE detail
CVE-2025-26598
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 29.4 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
18 source links · newest first
No excerpt available.
Vendor Advisorylists.debian.orgFeb 25, 2025, 4:15 PM- https://bugzilla.redhat.com/show_bug.cgi?id=2345254bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/security/cve/CVE-2025-26598access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:7458access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:7165access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:7163access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:3976access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2880access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2879access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2875access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2874access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2873access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2866access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2865access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2862access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2861access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2502access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2025:2500access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2025, 4:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-26596CVSS 7.8 · High
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap…
- CVE-2025-26595CVSS 7.8 · High
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to…
- CVE-2024-0409CVSS 7.8 · High
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as priva…
- CVE-2026-50264CVSS 7.8 · High
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments a…
- CVE-2024-0229CVSS 7.8 · High
An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This…
- CVE-2023-5367CVSS 7.8 · High
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XICha…