Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-62230

Опубликовано: 30 окт. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.20-1package
xwaylandunfixedpackage
xwaylandignoredtrixiepackage
xwaylandignoredbookwormpackage

Примечания

  • https://lists.x.org/archives/xorg-announce/2025-October/003635.html

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/99790a2c9205a52fbbec01f21a92c9b7f4ed1d8f

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/10c94238bdad17c11707e0bdaaa3a9cd54c504be

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/865089ca70840c0f13a61df135f7b44a9782a175 (xorg-server-21.1.19)

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/87fe2553937a99fd914ad0cde999376a3adc3839 (xorg-server-21.1.19)

EPSS

Процентиль: 2%
0.00015
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
8 дней назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

CVSS3: 7.3
nvd
8 дней назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

CVSS3: 7.3
msrc
6 дней назад

Xorg: xwayland: use-after-free in xkb client resource removal

CVSS3: 7.3
github
8 дней назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

suse-cvrf
5 дней назад

Security update for xorg-x11-server

EPSS

Процентиль: 2%
0.00015
Низкий