CVE-2025-26599 - X.Org and Xwayland Uninitialized Pointer Access Vulnerability

4 hours ago 3
ARTICLE AD BOX
CVE ID : CVE-2025-26599
Published : Feb. 25, 2025, 4:15 p.m. | 26 minutes ago
Description : An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized pointer later.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article