Use-After-Free Flaw in X.Org X Server's X Keyboard Extension Impacting Red Hat
CVE-2025-62230

7.3HIGH

What is CVE-2025-62230?

A flaw exists in the X.Org X server’s X Keyboard (Xkb) extension that occurs during the cleanup of client resources. Specifically, the software improperly frees certain data structures without detaching the associated resources, which can result in a use-after-free condition. This vulnerability may lead to memory corruption or application crashes when affected clients disconnect, creating potential instability and security issues within the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Red Hat Enterprise Linux 10 0:24.1.5-5.el10_0

Red Hat Enterprise Linux 10 0:24.1.5-5.el10_1

Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION 0:1.1.0-25.el6_10.15

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Jan-Niklas Sohn (Trend Micro Zero Day Initiative) for reporting this issue.
.