Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-62231

Опубликовано: 30 окт. 2025
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*
Версия до 21.1.19 (исключая)
cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:*
Версия до 24.1.9 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.1.30 (исключая)
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Версия от 7.2.5 (включая) до 7.2.5.12 (исключая)
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Версия от 7.3.2 (включая) до 7.3.3.3 (исключая)
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_els:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_els:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_tus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00281
Низкий

7.3 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.3
ubuntu
9 месяцев назад

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

CVSS3: 7.3
redhat
9 месяцев назад

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

CVSS3: 7.1
msrc
9 месяцев назад

Xorg: xmayland: value overflow in xkbsetcompatmap()

CVSS3: 7.3
debian
9 месяцев назад

A flaw was identified in the X.Org X server\u2019s X Keyboard (Xkb) ex ...

CVSS3: 7.3
github
9 месяцев назад

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

EPSS

Процентиль: 20%
0.00281
Низкий

7.3 High

CVSS3

Дефекты

CWE-190