Untriaged
Permalink
CVE-2025-62230
7.3 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): LOW
- Availability impact (A): HIGH
Xorg: xwayland: use-after-free in xkb client resource removal
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
References
Affected products
tigervnc
- *
xwayland
- <24.1.9
xorg-x11-server
- *
xorg-x11-server-Xwayland
- *