Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-62230

Опубликовано: 29 окт. 2025
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

Отчет

The Red Hat Product Security team has rated this vulnerability as Moderate.The flaw is a use-after-free in Xkb client resource cleanup that could lead to integrity and availability impacts if exploited. However, the X.Org server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, which limits the potential impact and prevents full system compromise.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2025:1943503.11.2025
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2025:2103511.11.2025
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2025:2266703.12.2025
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2025:2204025.11.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2025:2209625.11.2025
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2025:1943203.11.2025
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2025:1943403.11.2025
Red Hat Enterprise Linux 8tigervncFixedRHSA-2025:1990906.11.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupporttigervncFixedRHSA-2025:2207725.11.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2402653xorg: xwayland: Use-after-free in Xkb client resource removal

EPSS

Процентиль: 1%
0.00009
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
5 месяцев назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

CVSS3: 7.3
nvd
5 месяцев назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

CVSS3: 7.3
msrc
5 месяцев назад

Xorg: xwayland: use-after-free in xkb client resource removal

CVSS3: 7.3
debian
5 месяцев назад

A flaw was discovered in the X.Org X server\u2019s X Keyboard (Xkb) ex ...

CVSS3: 7.3
github
5 месяцев назад

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

EPSS

Процентиль: 1%
0.00009
Низкий

7.3 High

CVSS3