Use-After-Free Vulnerability in X.Org X Server and Xwayland
CVE-2025-62229
7.3HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 30 October 2025
What is CVE-2025-62229?
A flaw exists in the X.Org X server and Xwayland, specifically related to improper error handling during the processing of X11 Present extension notifications. This vulnerability can result in dangling pointers, which create a use-after-free condition, posing risks that include memory corruption or unexpected crashes. Such occurrences can potentially allow an attacker to execute arbitrary code or trigger a denial of service, compromising system stability and security.
Affected Version(s)
Red Hat Enterprise Linux 10 0:24.1.5-5.el10_0
Red Hat Enterprise Linux 10 0:24.1.5-5.el10_1
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.20.4-33.el7_9
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jan-Niklas Sohn (Trend Micro Zero Day Initiative) for reporting this issue.