• 公告ID (KylinSec-SA-2025-1152)

摘要:

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.

安全等级: Low

公告ID: KylinSec-SA-2025-1152

发布日期: 2025年3月3日

关联CVE: CVE-2025-26595  

  • 详细介绍

1. 漏洞描述

   

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2025-26595 KY3.4-5 tigervnc Unaffected
CVE-2025-26595 V6 tigervnc Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2025-1151 下一篇:KylinSec-SA-2025-1153