AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-26598

HIGH · CVSS 7.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-02-25 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. See the original NVD description below for full technical details.

CVE
CVE-2025-26598
Severity
HIGH
CVSS
7.8
EPSS
0.40%

Original NVD Description

An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.

Related CVEs

Other vulnerabilities affecting the same vendor(s)