CVE-2025-62231
7.3X.Org Foundation · Xwayland
An integer overflow in the X.Org X server Xkb extension allows a local attacker to cause memory corruption or a system crash via a specially crafted request to the XkbSetCompatMap function.
Executive summary
A critical integer overflow vulnerability in the X.Org X server Xkb extension, affecting various Red Hat Enterprise Linux distributions, poses a significant risk of memory corruption or service denial.
Vulnerability
This vulnerability is caused by improper bounds checking within the XkbSetCompatMap function of the Xkb extension. An attacker with local access can trigger an unsigned short integer overflow, which leads to memory corruption or an application crash.
Business impact
Successful exploitation of this flaw allows an attacker to cause a denial of service by crashing the X server, which may disrupt user sessions and business operations. Furthermore, memory corruption vulnerabilities often have the potential to be leveraged for arbitrary code execution in the context of the X server process. Given the CVSS score of 7.3, this issue is considered high severity, particularly in multi-user or shared workstation environments where local access is available.
Remediation
Immediate Action: Update Xwayland and the X server components to the versions specified in the relevant Red Hat Security Advisories (RHSA-2025:19432 through RHSA-2025:20958) or the upstream version 24.1.9.
Proactive Monitoring: Monitor system logs for unexpected X server restarts or segmentation faults, which may indicate attempted exploitation of the Xkb extension.
Compensating Controls: Restrict local access to the system to authorized users only, as the vulnerability requires local access to the X server environment to trigger the flaw.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk posed by memory corruption vulnerabilities in core graphical display components is significant, as they can compromise the stability and security of the entire desktop environment. Organizations should prioritize patching systems running Xwayland or X server, especially those exposed to untrusted local users. Please review the provided Red Hat errata references to identify the specific package versions required for your environment.
More X.Org Foundation CVEs
Sources
Originally found and disclosed by Red Hat would like to thank Jan-Niklas Sohn (Trend Micro Zero Day Initiative) for reporting this issue., per the CVE Program record.
- RHSA-2025:19432 Vendor advisory
- RHSA-2025:19433 Vendor advisory
- RHSA-2025:19434 Vendor advisory
- RHSA-2025:19435 Vendor advisory
- RHSA-2025:19489 Vendor advisory
- RHSA-2025:19623 Vendor advisory
- RHSA-2025:19909 Vendor advisory
- RHSA-2025:20958 Vendor advisory