Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-26600

Опубликовано: 25 фев. 2025
Источник: debian
EPSS Низкий

Описание

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.16-1package
xwaylandfixed2:24.1.6-1package
xwaylandignoredbookwormpackage

Примечания

  • https://lists.x.org/archives/xorg-announce/2025-February/003584.html

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/6e0f332ba4c8b8c9a9945dc9d7989bfe06f80e14

EPSS

Процентиль: 5%
0.00025
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.

CVSS3: 7.8
redhat
4 месяца назад

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.

CVSS3: 7.8
nvd
4 месяца назад

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.

CVSS3: 7.8
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7.8
github
4 месяца назад

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.

EPSS

Процентиль: 5%
0.00025
Низкий