CVE-2025-62230

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
References
Link Resource
https://access.redhat.com/errata/RHSA-2025:19432 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19433 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19434 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19435 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19489 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19623 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19909 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:20958 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:20960 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:20961 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:21035 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22040 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22041 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22051 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22055 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22056 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22077 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22096 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22164 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22167 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22364 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22365 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22426 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22427 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22667 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22729 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22742 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:22753 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:0031 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:0033 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:0034 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:0035 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:0036 Third Party Advisory
https://access.redhat.com/security/cve/CVE-2025-62230 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2402653 Issue Tracking Third Party Advisory
https://lists.x.org/archives/xorg-announce/2025-October/003635.html Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/10/28/7 Mailing List Patch
https://lists.debian.org/debian-lts-announce/2025/10/msg00033.html Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*
cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_aus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_els:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_els:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_tus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-10-30 06:15

Updated : 2026-07-01 15:13


NVD link : CVE-2025-62230

Mitre link : CVE-2025-62230

CVE.ORG link : CVE-2025-62230


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • enterprise_linux_tus
  • enterprise_linux_els
  • enterprise_linux_update_services_for_sap_solutions
  • enterprise_linux_aus
  • enterprise_linux_eus

ibm

  • vios
  • aix

x.org

  • xwayland
  • x_server

debian

  • debian_linux
CWE
CWE-416

Use After Free