CVE-2025-62230

Name
CVE-2025-62230
Description
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2025-62230
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2402653
vendor-advisory https://access.redhat.com/errata/RHSA-2025:19434
vendor-advisory https://access.redhat.com/errata/RHSA-2025:19432
vendor-advisory https://access.redhat.com/errata/RHSA-2025:19433
vendor-advisory https://access.redhat.com/errata/RHSA-2025:19435
vendor-advisory https://access.redhat.com/errata/RHSA-2025:19489
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/10/msg00033.html
vendor-advisory https://access.redhat.com/errata/RHSA-2025:19623
vendor-advisory https://access.redhat.com/errata/RHSA-2025:19909
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/10/28/7
vendor-advisory https://access.redhat.com/errata/RHSA-2025:20960
vendor-advisory https://access.redhat.com/errata/RHSA-2025:21035
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:20958
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:20961
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22041
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22051
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22055
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22056
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22040
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22077
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22096
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22164
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22167
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22364
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22365
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22426
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22427
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22667
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22729
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22742
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:22753
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0033
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0034
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0036
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0031
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0035
secalert@redhat.com https://lists.x.org/archives/xorg-announce/2025-October/003635.html

Match rules

CPE URI Source package Min version Max version
cpe:/o:redhat:enterprise_linux:10.0 shopxo >= 0:24.1.5-5.el10_0 < *
cpe:/a:redhat:enterprise_linux:8::appstream shopxo >= 0:21.1.3-19.el8_10 < *
cpe:/a:redhat:enterprise_linux:9::appstream shopxo >= 0:1.14.1-9.el9_6 < *
cpe:/a:redhat:enterprise_linux:8::appstream shopxo >= 0:1.15.0-8.el8_10 < *
cpe:/o:redhat:enterprise_linux:10.1 shopxo >= 0:24.1.5-5.el10_1 < *
cpe:/a:redhat:enterprise_linux:8::crb shopxo >= 0:1.20.11-27.el8_10 < *
cpe:/a:redhat:enterprise_linux:9::crb shopxo >= 0:1.20.11-32.el9_6 < *
cpe:/a:redhat:enterprise_linux:9::crb shopxo >= 0:23.2.7-5.el9_6 < *
cpe:/a:redhat:enterprise_linux:9::crb shopxo >= 0:23.2.7-5.el9_7 < *
cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* x_server >= None < 21.1.19
cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:* xwayland >= None < 24.1.9

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
xwayland edge-community 24.1.9-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 24.1.8-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 24.1.7-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 24.1.6-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 24.1.5-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 24.1.4-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 23.2.5-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 23.2.4-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 23.2.2-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland edge-community 22.1.8-r0 psykose <alice@ayaya.dev> fixed
xwayland edge-community 22.1.6-r0 psykose <alice@ayaya.dev> fixed
xwayland edge-community 21.1.4-r0 None possibly vulnerable
xwayland edge-community 21.1.0-r4 None possibly vulnerable
xwayland 3.23-community 24.1.9-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xwayland 3.22-community 24.1.9-r0 Simon Zeni <simon@bl4ckb0ne.ca> fixed
xorg-server edge-community 21.1.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
xorg-server 3.22-community 21.1.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed