AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-26599

HIGH · CVSS 7.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-02-25 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. See the original NVD description below for full technical details.

CVE
CVE-2025-26599
Severity
HIGH
CVSS
7.8
EPSS
0.40%

Original NVD Description

An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized pointer later.

Related CVEs

Other vulnerabilities affecting the same vendor(s)