cbcvebase.
CVE-2025-62230
published 2025-10-30

CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures…

high7.3CVSS 3.1
AVLACLPRLUINSUCHILAH
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianxorg-server< xorg-server 2:21.1.7-3+deb12u11 (bookworm)xorg-server 2:21.1.7-3+deb12u11 (bookworm)
debianxwayland< xorg-server 2:21.1.7-3+deb12u11 (bookworm)xorg-server 2:21.1.7-3+deb12u11 (bookworm)
msrcazl3_wayland_1.22.0-1_on_azure_linux_3.0
msrcazl3_xorg-x11-server-xwayland_24.1.6-2_on_azure_linux_3.0
x.orgxorg-server>= 0 < 2:1.20.11-1+deb11u172:1.20.11-1+deb11u17
x.orgxorg-server>= 0 < 2:21.1.7-3+deb12u112:21.1.7-3+deb12u11
x.orgxorg-server>= 0 < 2:21.1.16-1.3+deb13u12:21.1.16-1.3+deb13u1
x.orgxorg-server>= 0 < 2:21.1.20-12:21.1.20-1
x.orgxwayland< 24.1.924.1.9
x.orgxwayland>= 0 < 2:24.1.9-12:24.1.9-1

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
osv7.3HIGH