CVE-2025-62230: Debian Linux
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
Affected products
- Debian Debian Linux: version 11.0 only
- IBM Aix: from 7.2.5, before 7.2.5.12 (fixed in 7.2.5.12); from 7.3.2, before 7.3.3.3 (fixed in 7.3.3.3); version 7.3.4 only
- IBM Vios: from 4.1.0, before 4.1.1.30 (fixed in 4.1.1.30); version 4.1.2.0 only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Red Hat Enterprise Linux Aus: version 8.2 only; version 8.4 only; version 8.6 only
- Red Hat Enterprise Linux Els: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Eus: version 8.4 only; version 9.4 only
- Red Hat Enterprise Linux Tus: version 8.6 only; version 8.8 only
- Red Hat Enterprise Linux Update Services For SAP Solutions: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
- X.org X Server: before 21.1.19 (fixed in 21.1.19)
- X.org Xwayland: before 24.1.9 (fixed in 24.1.9)
Published 2025-10-30. Last modified 2026-07-01.