DEBIAN-CVE-2025-62231

Source
https://security-tracker.debian.org/tracker/CVE-2025-62231
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62231.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-62231
Upstream
  • CVE-2025-62231
Downstream
Published
2025-10-30T05:15:39.120Z
Modified
2025-11-30T05:16:49.457163Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H CVSS Calculator
Summary
[none]
Details

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

References

Affected packages

Debian:11
xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.20.11-1+deb11u17

Affected versions

2:1.*
2:1.20.11-1
2:1.20.11-1+deb11u1
2:1.20.11-1+deb11u2
2:1.20.11-1+deb11u3
2:1.20.11-1+deb11u4
2:1.20.11-1+deb11u5
2:1.20.11-1+deb11u6
2:1.20.11-1+deb11u7
2:1.20.11-1+deb11u8
2:1.20.11-1+deb11u9
2:1.20.11-1+deb11u10
2:1.20.11-1+deb11u11
2:1.20.11-1+deb11u12
2:1.20.11-1+deb11u13
2:1.20.11-1+deb11u14
2:1.20.11-1+deb11u15
2:1.20.11-1+deb11u16

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62231.json"
Debian:12
xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.1.7-3+deb12u11

Affected versions

2:21.*
2:21.1.7-3
2:21.1.7-3+deb12u1
2:21.1.7-3+deb12u2
2:21.1.7-3+deb12u3
2:21.1.7-3+deb12u4
2:21.1.7-3+deb12u5
2:21.1.7-3+deb12u6
2:21.1.7-3+deb12u7
2:21.1.7-3+deb12u8
2:21.1.7-3+deb12u9
2:21.1.7-3+deb12u10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62231.json"
xwayland

Package

Name
xwayland
Purl
pkg:deb/debian/xwayland?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:22.*
2:22.1.9-1
2:23.*
2:23.1.0-1
2:23.1.1-1
2:23.2.0-1
2:23.2.1-1
2:23.2.2-1
2:23.2.3-1
2:23.2.4-1
2:23.2.6-1
2:24.*
2:24.0.99.901-1
2:24.1.0-1
2:24.1.2-1
2:24.1.3-1
2:24.1.4-1
2:24.1.4-2
2:24.1.4-3
2:24.1.5-1
2:24.1.6-1
2:24.1.8-1
2:24.1.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62231.json"
Debian:13
xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.1.16-1.3+deb13u1

Affected versions

2:21.*
2:21.1.16-1.3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62231.json"
xwayland

Package

Name
xwayland
Purl
pkg:deb/debian/xwayland?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:24.*
2:24.1.6-1
2:24.1.8-1
2:24.1.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62231.json"
Debian:14
xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.1.20-1

Affected versions

2:21.*
2:21.1.16-1.3
2:21.1.18-1
2:21.1.18-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62231.json"
xwayland

Package

Name
xwayland
Purl
pkg:deb/debian/xwayland?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:24.1.9-1

Affected versions

2:24.*
2:24.1.6-1
2:24.1.8-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62231.json"