Rapid7

vulnerability

Gentoo Linux: CVE-2025-26597: X.Org X server, XWayland: Multiple Vulnerabilities

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
Feb 25, 2025
Added
Jun 13, 2025
Modified
Mar 31, 2026

Description

A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size.

Solutions

gentoo-linux-upgrade-x11-base-xorg-servergentoo-linux-upgrade-x11-base-xwayland
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.