Vulnerability Description
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| X.Org | X Server | < 21.1.19 |
| X.Org | Xwayland | < 24.1.9 |
| Ibm | Vios | >= 4.1.0, < 4.1.1.30 |
| Ibm | Aix | >= 7.2.5, < 7.2.5.12 |
| Debian | Debian Linux | 11.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Aus | 8.2 |
| Redhat | Enterprise Linux Els | 6.0 |
| Redhat | Enterprise Linux Eus | 8.4 |
| Redhat | Enterprise Linux Tus | 8.6 |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.6 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2025:19432Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19433Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19434Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19435Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19489Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19623Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19909Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20958Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20960Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20961Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:21035Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22051Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22055Third Party Advisory
FAQ
What is CVE-2025-62231?
CVE-2025-62231 is a vulnerability with a CVSS score of 7.3 (HIGH). A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends spe...
How severe is CVE-2025-62231?
CVE-2025-62231 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62231?
Check the references section above for vendor advisories and patch information. Affected products include: X.Org X Server, X.Org Xwayland, Ibm Vios, Ibm Aix, Debian Debian Linux.