Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-62230

Опубликовано: 30 окт. 2025
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*
Версия до 21.1.19 (исключая)
cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:*
Версия до 24.1.9 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.1.30 (исключая)
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Версия от 7.2.5 (включая) до 7.2.5.12 (исключая)
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Версия от 7.3.2 (включая) до 7.3.3.3 (исключая)
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_els:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_els:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_tus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00263
Низкий

7.3 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.3
ubuntu
9 месяцев назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

CVSS3: 7.3
redhat
9 месяцев назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

CVSS3: 7.3
msrc
9 месяцев назад

Xorg: xwayland: use-after-free in xkb client resource removal

CVSS3: 7.3
debian
9 месяцев назад

A flaw was discovered in the X.Org X server\u2019s X Keyboard (Xkb) ex ...

CVSS3: 7.3
github
9 месяцев назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

EPSS

Процентиль: 18%
0.00263
Низкий

7.3 High

CVSS3

Дефекты

CWE-416