cbcvebase.
CVE-2025-62230
published 2025-10-30

CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures…

PriorityP343high7.3CVSS 3.1
AVLACLPRLUINSUCHILAH
EPSS
0.27%
18.4th percentile
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianxorg-server< xorg-server 2:21.1.7-3+deb12u11 (bookworm)xorg-server 2:21.1.7-3+deb12u11 (bookworm)
debianxwayland< xorg-server 2:21.1.7-3+deb12u11 (bookworm)xorg-server 2:21.1.7-3+deb12u11 (bookworm)
ibmaix
ibmaix>= 7.2.5 < 7.2.5.127.2.5.12
ibmaix>= 7.3.2 < 7.3.3.37.3.3.3
ibmvios
ibmvios>= 4.1.0 < 4.1.1.304.1.1.30
msrcazl3_wayland_1.22.0-1_on_azure_linux_3.0
msrcazl3_xorg-x11-server-xwayland_24.1.6-2_on_azure_linux_3.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_aus
redhatenterprise_linux_aus
redhatenterprise_linux_aus
redhatenterprise_linux_els
redhatenterprise_linux_els
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_tus
redhatenterprise_linux_tus
redhatenterprise_linux_update_services_for_sap_solutions
redhatenterprise_linux_update_services_for_sap_solutions
redhatenterprise_linux_update_services_for_sap_solutions

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
osv7.3HIGH
vendor_debian7.3HIGH
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.