Corrective releases of X.Org Server 21.1.16 and the DDX component (Device-Dependent X) xwayland 24.1.6 have been published, enabling X.Org Server to run X11 applications in Wayland-based environments. The new version of X.Org Server addresses 8 vulnerabilities. These issues could potentially be exploited for privilege escalation in systems where the X server runs with root privileges and for remote code execution in configurations where access is granted through X11 session redirection using SSH.
Identified vulnerabilities:
- CVE-2025-26594 — use-after-free vulnerability in the root window cursor handler. This vulnerability has existed since the release of X11R6.6 in 2001.
- CVE-2025-26595 — buffer overflow in the XkbVModMaskText() function, caused by copying names of virtual modifiers into a fixed buffer without proper size checks. This vulnerability has existed since X11R6.1 (1996).
- CVE-2025-26596 — buffer overflow in the XkbWriteKeySyms() function, related to the size computed by the XkbSizeKeySyms() function not matching the size of data being written by the XkbWriteKeySyms() function. This vulnerability has existed since the first version of xkb.c included in X11R6 (1994).
- CVE-2025-26597 — buffer overflow in the XkbChangeTypesOfKey() function due to an incorrect size of the symbol code table. This vulnerability has existed since the release of X11R6.1 (1996).
- CVE-2025-26598 — out-of-bounds data access in the CreatePointerBarrierClient() function, caused by returning an incorrect index in the list when failing to find a pointer device. This vulnerability has existed since xorg-server 1.14.0 (2013).
- CVE-2025-26599 — access via an uninitialized pointer in the compRedirectWindow() function when unable to allocate memory for a bitmap. This vulnerability has existed since Xorg 6.8.0 (2004).
- CVE-2025-26600 — use-after-free access in the PlayReleasedEvents() function when extracting a stalled device with unprocessed events. This vulnerability has existed since X11R5 (1991).
- CVE-2025-26601 — use-after-free access in the SyncInitTrigger() function. This vulnerability has existed since X11R6 (1994).
Source: opennet.ru
