CVE-2025-62229

Updated: 2025-11-03 11:18:04.270659

Description:

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU xorg-x11-server-Xwayland 21.1.3 7.3 HIGH Released CLSA-2025:1764081820 2025-11-25 21:13:31
AlmaLinux 9.2 ESU tigervnc 1.12.0 7.3 HIGH Released CLSA-2025:1763138343 2025-11-14 22:32:28
CentOS 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765223770 2025-12-20 04:35:30
Oracle Linux 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765209058 2025-12-08 17:19:48
Oracle Linux 7 ELS tigervnc 1.8.0 7.3 HIGH Released CLSA-2025:1765208809 2025-12-08 17:19:56
RHEL 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765209523 2025-12-08 17:19:50
TuxCare 9.6 ESU tigervnc 1.14.1 7.3 HIGH Already Fixed 2025-12-16 17:38:38
TuxCare 9.6 ESU xorg-x11-server-Xwayland 23.2.7 7.3 HIGH Already Fixed 2025-12-16 17:38:21