Aller au contenu

Fiche vulnérabilité

CVE-2025-26594 : faille élevée tigervnc tigervnc (CVSS 7.8)

Description

A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
25 févr. 2025
Dernière mise à jour
29 juin 2026

Produits concernés

  • tigervnc tigervnc
  • x.org x server
  • x.org xwayland
  • redhat enterprise linux

Références

Rechercher une autre vulnérabilité dans la base CVE