cbcvebase.
CVE-2025-62229
published 2025-10-30

CVE-2025-62229: A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation…

high7.3CVSS 3.1
AVLACLPRLUINSUCLIHAH
A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianxorg-server< xorg-server 2:21.1.7-3+deb12u11 (bookworm)xorg-server 2:21.1.7-3+deb12u11 (bookworm)
debianxwayland< xorg-server 2:21.1.7-3+deb12u11 (bookworm)xorg-server 2:21.1.7-3+deb12u11 (bookworm)
msrcazl3_wayland_1.22.0-1_on_azure_linux_3.0
msrcazl3_xorg-x11-server-xwayland_24.1.6-2_on_azure_linux_3.0
x.orgxorg-server>= 0 < 2:1.20.11-1+deb11u172:1.20.11-1+deb11u17
x.orgxorg-server>= 0 < 2:21.1.7-3+deb12u112:21.1.7-3+deb12u11
x.orgxorg-server>= 0 < 2:21.1.16-1.3+deb13u12:21.1.16-1.3+deb13u1
x.orgxorg-server>= 0 < 2:21.1.20-12:21.1.20-1
x.orgxwayland>= 0 < 2:24.1.9-12:24.1.9-1
x.orgxwayland>= 1.15.0 < 24.1.924.1.9

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
osv7.3HIGH