A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4353-1 | xorg-server security update |
Debian DSA |
DSA-6044-1 | xorg-server security update |
Fixes
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References
History
Thu, 30 Oct 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. | |
| Title | Xorg: xwayland: use-after-free in xkb client resource removal | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-10-30T05:19:40.445Z
Reserved: 2025-10-09T04:46:44.074Z
Link: CVE-2025-62230
No data.
Status : Received
Published: 2025-10-30T06:15:45.593
Modified: 2025-10-30T06:15:45.593
Link: CVE-2025-62230
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA