Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-62229

Опубликовано: 30 окт. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.20-1package
xwaylandfixed2:24.1.9-1package
xwaylandignoredtrixiepackage
xwaylandignoredbookwormpackage

Примечания

  • https://lists.x.org/archives/xorg-announce/2025-October/003635.html

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/5a4286b13f631b66c20f5bc8db7b68211dcbd1d0

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/554dfabfbc23c3e74997e09c13f5424a60daf9ee (xorg-server-21.1.19)

EPSS

Процентиль: 1%
0.0001
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
5 месяцев назад

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

CVSS3: 7.3
redhat
5 месяцев назад

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

CVSS3: 7.3
nvd
5 месяцев назад

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

CVSS3: 7.8
msrc
5 месяцев назад

Xorg: xmayland: use-after-free in xpresentnotify structure creation

CVSS3: 7.3
github
5 месяцев назад

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

EPSS

Процентиль: 1%
0.0001
Низкий