CVE-2025-62231

Updated: 2025-11-03 11:18:07.23718

Description:

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU xorg-x11-server-Xwayland 21.1.3 7.3 HIGH Released CLSA-2025:1764081820 2025-11-25 21:13:30
AlmaLinux 9.2 ESU tigervnc 1.12.0 7.3 HIGH Released CLSA-2025:1763138343 2025-11-14 22:32:26
CentOS 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765223770 2025-12-20 04:35:25
Oracle Linux 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765209058 2025-12-08 17:19:45
Oracle Linux 7 ELS tigervnc 1.8.0 7.3 HIGH Released CLSA-2025:1765208809 2025-12-08 17:19:54
RHEL 7 ELS xorg-x11-server 1.20.4 7.3 HIGH Released CLSA-2025:1765209523 2025-12-08 17:19:46
TuxCare 9.6 ESU tigervnc 1.14.1 7.3 HIGH Already Fixed 2025-12-16 17:38:37
TuxCare 9.6 ESU xorg-x11-server-Xwayland 23.2.7 7.3 HIGH Already Fixed 2025-12-16 17:38:21