CVE-2025-26601
7.8
HIGH
CVSS 3.1
EPSS 0.03%
Description
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing a use-after-free when the alarm eventually triggers.
How to fix CVE-2025-26601
To remediate CVE-2025-26601, upgrade the affected package to a fixed version below.
- —upgrade to 2:1.20.11-1+deb11u15 or later
- —no fix listed
Is CVE-2025-26601 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2:1.20.11-1+deb11u15
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |