CVE-2025-62231
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
- CVSS 3.1
- 7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- x.org/x server · x.org/xwayland · ibm/vios · ibm/aix · debian/debian linux · redhat/enterprise linux · redhat/enterprise linux aus · redhat/enterprise linux els · redhat/enterprise linux eus · redhat/enterprise linux tus · redhat/enterprise linux update services for sap solutions
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2025:19432Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19433Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19434Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19435Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19489Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19623Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19909Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20958Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20960Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20961Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:21035Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22051Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22055Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22056Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22077Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22096Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22167Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22364Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22365Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22426Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22427Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22667Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22729Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22742Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22753Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:0031Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:0033Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.