Vulnerability Description
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| X.Org | X Server | < 21.1.19 |
| X.Org | Xwayland | < 24.1.9 |
| Ibm | Vios | >= 4.1.0, < 4.1.1.30 |
| Ibm | Aix | >= 7.2.5, < 7.2.5.12 |
| Debian | Debian Linux | 11.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Aus | 8.2 |
| Redhat | Enterprise Linux Els | 6.0 |
| Redhat | Enterprise Linux Eus | 8.4 |
| Redhat | Enterprise Linux Tus | 8.6 |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.6 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2025:19432Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19433Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19434Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19435Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19489Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19623Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19909Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20958Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20960Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20961Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:21035Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22051Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22055Third Party Advisory
FAQ
What is CVE-2025-62230?
CVE-2025-62230 is a vulnerability with a CVSS score of 7.3 (HIGH). A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources,...
How severe is CVE-2025-62230?
CVE-2025-62230 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62230?
Check the references section above for vendor advisories and patch information. Affected products include: X.Org X Server, X.Org Xwayland, Ibm Vios, Ibm Aix, Debian Debian Linux.