CVE-2025-62231
Last modified
CVE-2025-62231 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X.Org | X Server | < 21.1.19 |
| X.Org | Xwayland | < 24.1.9 |
| Ibm | Vios | >= 4.1.0, < 4.1.1.30 |
| Ibm | Vios | 4.1.2.0 |
| Ibm | Aix | >= 7.2.5, < 7.2.5.12 |
| Ibm | Aix | >= 7.3.2, < 7.3.3.3 |
| Ibm | Aix | 7.3.4 |
| Debian | Debian Linux | 11.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux | 10.0 |
| Redhat | Enterprise Linux Aus | 8.2 |
| Redhat | Enterprise Linux Aus | 8.4 |
| Redhat | Enterprise Linux Aus | 8.6 |
| Redhat | Enterprise Linux Els | 6.0 |
| Redhat | Enterprise Linux Els | 7.0 |
| Redhat | Enterprise Linux Eus | 8.4 |
| Redhat | Enterprise Linux Eus | 9.4 |
| Redhat | Enterprise Linux Tus | 8.6 |
| Redhat | Enterprise Linux Tus | 8.8 |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.6 |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.8 |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.0 |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.2 |
References
- https://access.redhat.com/errata/RHSA-2025:19432Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19433Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19434Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19435Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19489Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19623Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19909Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20958Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20960Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:20961Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:21035Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22051Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22055Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22056Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22077Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22096Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22167Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22364Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22365Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22426Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22427Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22667Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22729Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22742Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:22753Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:0031Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:0033Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:0034Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:0035Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:0036Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-62231Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2402660Issue Tracking, Third Party Advisory
- https://lists.x.org/archives/xorg-announce/2025-October/003635.htmlMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/10/28/7Mailing List, Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00033.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-62231?
How severe is CVE-2025-62231?
How do I fix CVE-2025-62231?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62223User interface (ui) misrepresentation of critical informatio…4.3
- CVE-2025-62224User interface (ui) misrepresentation of critical informatio…3.5
- CVE-2025-62225Optical Disc Archive Software provided by Sony Corporation r…8.4
- CVE-2025-62228Apache Flink CDC version 3.4.0 was vulnerable to a SQL injec…8.8
- CVE-2025-62229A flaw was found in the X.Org X server and Xwayland when pro…7.3
- CVE-2025-62230A flaw was discovered in the X.Org X server’s X Keyboard (Xk…7.3
- CVE-2025-62232Sensitive data exposure via logging in basic-auth leads to p…7.5
- CVE-2025-62233Deserialization of Untrusted Data vulnerability in Apache Do…6.3
- CVE-2025-62235Authentication Bypass by Spoofing vulnerability in Apache Ni…8.1
- CVE-2025-62236The Frontier Airlines website has a publicly available endpo…6.9
- CVE-2025-62237Stored cross-site scripting (XSS) vulnerability in Commerce’…5.4
- CVE-2025-62238Stored cross-site scripting (XSS) vulnerability on the Membe…5.4
Are you affected by CVE-2025-62231?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
