A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4353-1 | xorg-server security update |
Debian DSA |
DSA-6044-1 | xorg-server security update |
Fixes
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References
History
Thu, 30 Oct 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service. | |
| Title | Xorg: xmayland: use-after-free in xpresentnotify structure creation | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-10-30T05:28:48.131Z
Reserved: 2025-10-09T04:46:44.074Z
Link: CVE-2025-62229
No data.
Status : Received
Published: 2025-10-30T06:15:45.300
Modified: 2025-10-30T06:15:45.300
Link: CVE-2025-62229
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA