cbcvebase.
CVE-2025-62231
published 2025-10-30

CVE-2025-62231: A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned…

PriorityP344high7.3CVSS 3.1
AVLACLPRLUINSUCHILAH
EPSS
0.28%
20.2th percentile
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianxorg-server< xorg-server 2:21.1.7-3+deb12u11 (bookworm)xorg-server 2:21.1.7-3+deb12u11 (bookworm)
debianxwayland< xorg-server 2:21.1.7-3+deb12u11 (bookworm)xorg-server 2:21.1.7-3+deb12u11 (bookworm)
ibmaix
ibmaix>= 7.2.5 < 7.2.5.127.2.5.12
ibmaix>= 7.3.2 < 7.3.3.37.3.3.3
ibmvios
ibmvios>= 4.1.0 < 4.1.1.304.1.1.30
msrcazl3_wayland_1.22.0-1_on_azure_linux_3.0
msrcazl3_xorg-x11-server-xwayland_24.1.6-2_on_azure_linux_3.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_aus
redhatenterprise_linux_aus
redhatenterprise_linux_aus
redhatenterprise_linux_els
redhatenterprise_linux_els
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_tus
redhatenterprise_linux_tus
redhatenterprise_linux_update_services_for_sap_solutions
redhatenterprise_linux_update_services_for_sap_solutions
redhatenterprise_linux_update_services_for_sap_solutions

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
osv7.3HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.