CVE-2025-62229
7.3X.Org Foundation · X Server and Xwayland
A use-after-free vulnerability exists in the X.Org X server and Xwayland when processing X11 Present extension notifications, potentially allowing for code execution or a denial of service.
Executive summary
A critical use-after-free vulnerability in the X.Org X server and Xwayland allows local attackers to trigger memory corruption and potentially execute arbitrary code.
Vulnerability
This flaw stems from improper error handling during X11 Present extension notification creation, which results in dangling pointers. According to the CVSS vector (AV:L/PR:L/UI:N), this vulnerability requires an authenticated local user to trigger.
Business impact
The ability to execute arbitrary code or cause a system crash poses a significant risk to environment stability and data integrity. While the CVSS score of 7.3 reflects a High severity, the impact is localized to systems where an attacker has achieved local access. Organizations running these versions on multi-user systems or shared infrastructure face the highest risk of privilege escalation or service disruption.
Remediation
Immediate Action: Update X.Org X server and Xwayland packages to the versions specified in the vendor security advisories linked in the reference section. For Red Hat users, apply the patches provided in the relevant RHSA errata.
Proactive Monitoring: Monitor system logs for frequent X server crashes or segmentation faults, which may indicate attempted exploitation of this memory corruption flaw.
Compensating Controls: Since this is a local exploit, strictly enforce the principle of least privilege and limit access to the local console or graphical desktop environment to authorized personnel only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability should be prioritized for patching on all affected workstations and servers. Administrators should follow the specific guidance provided by their distribution maintainers, such as Red Hat, to ensure the correct patched versions are deployed across the enterprise.
More X.Org Foundation CVEs
Sources
Originally found and disclosed by Red Hat would like to thank Jan-Niklas Sohn (Trend Micro Zero Day Initiative) for reporting this issue., per the CVE Program record.
- RHSA-2025:19432 Vendor advisory
- RHSA-2025:19433 Vendor advisory
- RHSA-2025:19434 Vendor advisory
- RHSA-2025:19435 Vendor advisory
- RHSA-2025:19489 Vendor advisory
- RHSA-2025:19623 Vendor advisory
- RHSA-2025:19909 Vendor advisory
- RHSA-2025:20958 Vendor advisory