Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-62231

Опубликовано: 30 окт. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.3

Описание

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
plucky

not-affected

code not present
questing

not-affected

code not present
upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/xenial

not-affected

code not present
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

code not present
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

released

2:21.1.21-1ubuntu1
esm-infra-legacy/trusty

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

needs-triage

jammy

released

2:21.1.4-2ubuntu1.7~22.04.16
noble

released

2:21.1.12-1ubuntu1.5
plucky

released

2:21.1.16-1ubuntu1.2
questing

released

2:21.1.18-1ubuntu1.1
upstream

released

21.1.19

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/xenial

needs-triage

jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

needs-triage

jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

2:24.1.9-1
jammy

released

2:22.1.1-1ubuntu0.20
noble

released

2:23.2.6-1ubuntu0.7
plucky

released

2:24.1.6-1ubuntu0.2
questing

released

2:24.1.6-1ubuntu1.1
upstream

released

24.1.9

Показывать по

EPSS

Процентиль: 4%
0.00018
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
3 месяца назад

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

CVSS3: 7.1
msrc
3 месяца назад

Xorg: xmayland: value overflow in xkbsetcompatmap()

CVSS3: 7.3
debian
3 месяца назад

A flaw was identified in the X.Org X server\u2019s X Keyboard (Xkb) ex ...

CVSS3: 7.3
github
3 месяца назад

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

CVSS3: 7.3
fstec
3 месяца назад

Уязвимость функции XkbSetCompatMap реализации протокола Wayland для X.Org XWayland и реализации сервера X Window System X.Org Server, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 4%
0.00018
Низкий

7.3 High

CVSS3