CVE-2025-62230

Updated: 2025-11-03 11:18:05.647061

Description:

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU xorg-x11-server-Xwayland 21.1.3 7.3 HIGH Released CLSA-2025:1764081820 2025-11-25 21:13:29
AlmaLinux 9.2 ESU tigervnc 1.12.0 7.3 HIGH Released CLSA-2025:1763125295 2025-11-14 13:59:47
CentOS 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765223770 2025-12-20 04:35:20
Oracle Linux 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765209058 2025-12-08 17:19:41
Oracle Linux 7 ELS tigervnc 1.8.0 7.3 HIGH Released CLSA-2025:1765208809 2025-12-08 17:19:53
RHEL 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765209523 2025-12-08 17:19:43
TuxCare 9.6 ESU tigervnc 1.14.1 7.3 HIGH Already Fixed 2025-12-16 17:38:37
TuxCare 9.6 ESU xorg-x11-server-Xwayland 23.2.7 7.3 HIGH Already Fixed 2025-12-16 17:38:20