CVE-2025-62230

Published: October 30, 2025Last modified: November 5, 2025

Description

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

Severity score breakdown

ParameterValue
Base score7.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactLOW
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSxorg-serverFixed (21.1.20-r0)
25 LTSxorg-serverFixed (21.1.20-r0)
Streamxorg-serverFixed (21.1.20-r0)

References

ON THIS PAGE