Description
An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized pointer later.
INFO
Published Date :
2025-02-25T15:55:02.964Z
Last Modified :
2026-04-06T12:53:26.527Z
Source :
redhat
AFFECTED PRODUCTS
The following products are affected by CVE-2025-26599 vulnerability.
| Vendors | Products |
|---|---|
| Redhat |
|
| Tigervnc |
|
| X.org |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-26599.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact